Description
MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw in the plugin install/uninstall service of MineAdmin. Unsanitized identifier values are concatenated into file system paths, allowing an attacker who can supply arbitrary identifiers to read, install, or delete files outside the intended plugin area. This can lead to arbitrary execution of composer commands and potentially arbitrary code execution. The weakness is identified as directory traversal (CWE‑22).

Affected Systems

This flaw affects the MineAdmin backend management system prior to version 3.2.0‑alpha.2. The issue manifests when the app‑store plugin service processes user‑supplied identifiers without proper sanitization. Systems running any version older than the patched release are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. No EPSS score is available, and the flaw is not listed in CISA KEV. Attackers can exploit the flaw remotely through the web interface by providing crafted identifier values in the plugin install/uninstall requests. Once the path traversal is successful, the attacker can read or modify any file under the application directory and trigger composer commands, leading to code execution. The vulnerability requires network access to the MineAdmin web console and does not depend on user authentication beyond access to the plugin API.

Generated by OpenCVE AI on September 30, 2026 at 19:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MineAdmin to version 3.2.0‑alpha.2 or later, where the plugin identifier is sanitized.
  • If an upgrade is not immediately possible, block external access to the plugin install/uninstall endpoints or enforce strict ACLs so only trusted administrators can invoke them.
  • As a temporary measure, manually audit and remove any unintended files in directories that could be accessed via path traversal, and restrict the web root permissions to limit write access.
  • Verify that the web server process runs with the least privileges, reducing impact if exploitation occurs.

Generated by OpenCVE AI on September 30, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-59xm-4m8c-g3xj MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mineadmin
Mineadmin mineadmin
Vendors & Products Mineadmin
Mineadmin mineadmin

Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.
Title MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mineadmin Mineadmin
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T17:26:11.618Z

Reserved: 2026-06-16T16:16:32.628Z

Link: CVE-2026-55224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:37.713

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-55224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')