Executive brief
LupinLin1 jimeng-web-mcp is a Model Context Protocol (MCP) server used to interface with AI image and video generation services. A security flaw in version 2.1.2 causes the application to record sensitive information into its log files. If these logs are accessed by unauthorized individuals, it could lead to the exposure of confidential data or credentials, potentially compromising the security of the AI service integration.
Technical details
A vulnerability classified as CWE-532 (Insertion of Sensitive Information into Log File) exists in LupinLin1 jimeng-web-mcp v2.1.2. The application improperly records sensitive data—potentially including API keys, session tokens, or user data—into plaintext log files. An attacker with access to the server's file system or log management interface could retrieve this information to facilitate further attacks. The vulnerability is reachable via standard network operations that trigger logging events. No specific patch version was confirmed in the advisory, though users are advised to secure log access and monitor for sensitive data leakage.
Affected products
- LupinLin1 jimeng-web-mcp 2.1.2
Timeline
- 2026-03-09: disclosed: Vulnerability disclosed via GitHub Gist and NVD.
- 2026-03-09: advisory