Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-59xm-4m8c-g3xj | MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall |
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2. | |
| Title | MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-30T17:26:11.618Z
Reserved: 2026-06-16T16:16:32.628Z
Link: CVE-2026-55224
No data.
Status : Deferred
Published: 2026-09-30T18:18:37.713
Modified: 2026-09-30T19:57:08.043
Link: CVE-2026-55224
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:00:11Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Github GHSA