๐Ÿ” CVE Alert

CVE-2026-55224

UNKNOWN 0.0

MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.

CWE CWE-22
Vendor mineadmin
Product mineadmin
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for mineadmin mineadmin

Be the first to know when new unknown vulnerabilities affecting mineadmin mineadmin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mineadmin / MineAdmin
< 3.2.0-alpha.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mineadmin/MineAdmin/security/advisories/GHSA-59xm-4m8c-g3xj github.com: https://github.com/mineadmin/MineAdmin/pull/728 github.com: https://github.com/mineadmin/MineAdmin/commit/ca41902a2a5422676227e5088f4cc1dec06044f1 github.com: https://github.com/mineadmin/MineAdmin/releases/tag/v3.2.0-alpha.2