๐Ÿ” CVE Alert

CVE-2026-48787

UNKNOWN 0.0

gin-vue-admin vulnerable to RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulnerability by injecting attacker-controlled Go source code through POST /autoCode/addFunc, and then invoking POST /autoCode/mcpStart to trigger a rebuild and restart of the standalone MCP service. This allows arbitrary operating system commands to be executed on the server with the privileges of the application process. Successful exploitation may lead to remote code execution (RCE), modification of backend source code or runtime logic, deployment of persistent backdoors, access to or manipulation of application data and configuration, and further impact on local resources running under the same service account or privilege context. The risk is highest in deployments that retain the source tree, allow writes to source files, and support local build or startup of standalone MCP components. In environments using binary-only releases, read-only filesystems, or with local build capabilities removed, the exploitability of the full attack chain is significantly reduced. However, once the online code-generation capability and MCP-hosted startup workflow are enabled, the overall security impact may reach high to critical severity. As of time of publication, it is unknown if a patched version is available. As a workaround, enforce strict allowlist validation on path- and identifier-related fields such as `humpPackageName`, `packageName`, `FuncName`, and `Router`, and only permit safe identifier formats.

CWE CWE-78
Vendor flipped-aurora
Product gin-vue-admin
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for flipped-aurora gin-vue-admin

Be the first to know when new unknown vulnerabilities affecting flipped-aurora gin-vue-admin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

flipped-aurora / gin-vue-admin
= 2.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-22cv-9jv2-6m62