Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-59xm-4m8c-g3xj | MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall |
Fri, 02 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mineadmin
Mineadmin mineadmin |
|
| Vendors & Products |
Mineadmin
Mineadmin mineadmin |
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2. | |
| Title | MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T16:28:25.497Z
Reserved: 2026-06-16T16:16:32.628Z
Link: CVE-2026-55224
Updated: 2026-10-02T16:28:15.857Z
Status : Deferred
Published: 2026-09-30T18:18:37.713
Modified: 2026-10-02T17:17:06.293
Link: CVE-2026-55224
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:15:10Z
Github GHSA