CVE-2025-70040

An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lupinlin1:jimeng_web_mcp_server:2.1.2:*:*:*:*:*:*:*

History

21 May 2026, 17:16

Type Values Removed Values Added
First Time Lupinlin1
Lupinlin1 jimeng Web Mcp Server
CPE cpe:2.3:a:lupinlin1:jimeng_web_mcp_server:2.1.2:*:*:*:*:*:*:*
References () https://gist.github.com/zcxlighthouse/73b4ea07d1056ca9f100d11bfb4c8aa5 - () https://gist.github.com/zcxlighthouse/73b4ea07d1056ca9f100d11bfb4c8aa5 - Third Party Advisory
References () https://github.com/LupinLin1 - () https://github.com/LupinLin1 - Product
References () https://github.com/LupinLin1/jimeng-web-mcp - () https://github.com/LupinLin1/jimeng-web-mcp - Product

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) Un problema relacionado con CWE-532: Inserción de información sensible en un archivo de registro fue descubierto en LupinLin1 jimeng-web-mcp v2.1.2. Esto permite a un atacante obtener información sensible.

09 Mar 2026, 17:16

Type Values Removed Values Added
CWE CWE-532
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

09 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 16:16

Updated : 2026-05-21 17:16


NVD link : CVE-2025-70040

Mitre link : CVE-2025-70040

CVE.ORG link : CVE-2025-70040


JSON object : View

Products Affected

lupinlin1

  • jimeng_web_mcp_server
CWE
CWE-532

Insertion of Sensitive Information into Log File