Executive brief
A vulnerability in the jimeng-mcp library allows remote attackers to access sensitive files on the host server. This library, which handles image and video generation tasks, fails to properly restrict file access paths. An attacker could exploit this to read internal system files or configuration data, potentially leading to further compromise of the application or its data.
Technical details
A path traversal vulnerability exists in the getFileContent, uploadCoverFile, generateImage, and generateVideo functions within src/api.ts of c-rick jimeng-mcp 1.10.0. The root cause is the improper validation of the 'filePath' argument, which is passed directly to path.resolve() and fs.promises.readFile() without root-boundary enforcement. A remote attacker with low privileges can provide a manipulated path (e.g., using '../' sequences) to read arbitrary files from the local file system. Additionally, the same parameter is susceptible to Server-Side Request Forgery (SSRF) as it is passed to axios.get() when a URL scheme is detected without an allowlist. As of the advisory date, no official patch has been released.
Affected products
- c-rick jimeng-mcp 1.10.0
Timeline
- 2026-04-27: disclosed: Issue reported on GitHub repository
- 2026-05-25: advisory: CVE published via VulDB/NVD