CVE-2026-55224 Details
Description
MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.
A path traversal vulnerability has been identified in MineAdmin versions prior to 3.2.0-alpha.2. The issue arises in the app-store plugin service, which concatenates unsanitized user-supplied identifier values directly into file system paths. This flaw allows an attacker to use path traversal sequences to manipulate the file path, potentially leading to unauthorized reading, installation, or uninstallation of plugins from arbitrary directories. Additionally, it could allow the execution of arbitrary composer commands. The vulnerability is exploitable by any authenticated user due to a missing permission check in the application's middleware.
The vulnerability has been patched in MineAdmin version 3.2.0-alpha.2. Users should update to this version. For versions prior to 3.2.0-alpha.2, it is recommended to validate and sanitize the 'identifier' parameter to reject path traversal sequences before concatenating them into file paths.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mineadmin/MineAdmin/commit/ca41902a2a5422676227e5088f4cc1dec06044f1 | [email protected] | Source CodeVendor |
| https://github.com/mineadmin/MineAdmin/pull/728 | [email protected] | Issue TrackingVendor |
| https://github.com/mineadmin/MineAdmin/releases/tag/v3.2.0-alpha.2 | [email protected] | Release NotesVendor |
| https://github.com/mineadmin/MineAdmin/security/advisories/GHSA-59xm-4m8c-g3xj | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MineAdmin | <= 99.99.99 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion