CVE-2026-55224
published 2026-08-18CVE-2026-55224: MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall ## Path Traversal via Unsanitized Identifier in Plugin…
high7.5
EXPLOIT
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
## Path Traversal via Unsanitized Identifier in Plugin Install/Uninstall
### Summary
The app-store plugin service concatenates unsanitized user-supplied `identifier` values directly into file system paths. An attacker can use path traversal sequences (e.g., `../`) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands.
### Vulnerable Code
**File:** `plugin/mine-admin/app-store/src/Service/Service.php`
```php
// Line 32 - download(): path traversal via identifier
public function download(array $params): bool
{
if (empty($params['identifier']) || empty($params['version'])) {
$this->throwParamsFail();
}
$service = make(AppStoreServiceImpl::class);
if (! is_dir(BASE_PATH . '/plugin/' . $params['identifier'])) { // Path traversal
$result = $service->download($params['identifier'], $params['version']);
// ...
}
return true;
}
// Line 48 - install(): path traversal + Plugin::install() with raw identifier
public function install(array $params): bool
{
// ...
$path = BASE_PATH . '/plugin/' . $params['identifier']; // Path traversal
if (file_exists($path . '/install.lock')) {
$this->throwAppInstalled();
}
Plugin::install($params['identifier']); // May run composer commands with traversal path
return true;
}
// Line 70 - unInstall(): same pattern
public function unInstall(array $params): bool
{
// ...
$path = BASE_PATH . '/plugin/' . $params['identifier']; // Path traversal
Plugin::uninstall($params['identifier']); // Arbitrary uninstall
return true;
}
```
**File:** `plugin/mine-admin/app-store/src/Controller/IndexController.php` (lines 25-26)
```php
#[Controller(prefix: 'admin/plugin/store')]
#[Middleware(middleware: AccessTokenMiddleware::class, priority: 100)]
// Only AccessTokenMiddleware -- no PermissionMiddleware (see GM-4340)
```
### Proof of Concept
```bash
# Install a "plugin" from a traversed path, poAffected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mineadmin | mineadmin | >= 0 < 3.2.0-alpha.2 | 3.2.0-alpha.2 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCE
nuclei·CVSS 7.5
CVE-2026-55224 MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCE
MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCE
MineAdmin versions before 3.2.0-alpha.2 contain a path traversal vulnerability in the app-store plugin service. The identifier parameter is concatenated into filesystem paths without sanitization.
Template:
id: CVE-2026-55224
info:
name: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCE
author: afanti
severity: high
description: |
MineAdmin versions before 3.2.0-alpha.2 contain a path traversal vulnerability in the app-store plugin service. The identifier parameter is concatenated into filesystem paths without sanitization.
impact: |
Authenticated users can escape the plugin directory to read or manipulate arbitrary files/directories.
remediation: |
Upgrade MineAdmin to version 3.2.0-alpha.2 or later.
reference:
- https://
No writeups or analysis indexed.
2026-08-18
Published