CVE-2026-9473

Source
https://cve.org/CVERecord?id=CVE-2026-9473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-9473
Published
2026-05-25T16:15:10Z
Modified
2026-08-12T03:51:41Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
c-rick jimeng-mcp api.ts generateVideo path traversal
Details

A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9473.json"
}
References

Affected packages

Git / github.com/c-rick/jimeng-mcp

Affected ranges

Type
GIT
Repo
https://github.com/c-rick/jimeng-mcp
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.10.0"
        },
        {
            "last_affected": "1.10.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.10.0
v1.*
v1.10.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9473.json"