目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-55224— MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

一分钟漏洞结论

影响对象
mineadmin mineadmin/mineadmin
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Path Traversal via Unsanitized Identifier in Plugin Install/Uninstall Summary The app-store plugin service concatenates unsanitized user-supplied values directly into file system paths. An attacker can use path traversal sequences (e.g., ) to read, install, or

RESERVED 预收录记录 — 待 CVE 官方发布
CVE Program 当前仍将该编号标记为 RESERVED。以下内容来自已审核的公开安全公告,可能继续变更;正式 CVE 记录发布后将自动替换。 · GitHub Advisory · 2026-08-18
CVSS 8.7 · High

公开利用映射 1

获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-55224 基础信息

漏洞信息

Shenlong is analyzing...


对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
来源: GitHub Advisory · Provisional
Vulnerability Description
## Path Traversal via Unsanitized Identifier in Plugin Install/Uninstall ### Summary The app-store plugin service concatenates unsanitized user-supplied `identifier` values directly into file system paths. An attacker can use path traversal sequences (e.g., `../`) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. ### Vulnerable Code **File:** `plugin/mine-admin/app-store/src/Service/Service.php` ```php // Line 32 - download(): path traversal via identifier public function download(array $params): bool { if (empty($params['identifier']) || empty($params['version'])) { $this->throwParamsFail(); } $service = make(AppStoreServiceImpl::class); if (! is_dir(BASE_PATH . '/plugin/' . $params['identifier'])) { // Path traversal $result = $service->download($params['identifier'], $params['version']); // ... } return true; } // Line 48 - install(): path traversal + Plugin::install() with raw identifier public function install(array $params): bool { // ... $path = BASE_PATH . '/plugin/' . $params['identifier']; // Path traversal if (file_exists($path . '/install.lock')) { $this->throwAppInstalled(); } Plugin::install($params['identifier']); // May run composer commands with traversal path return true; } // Line 70 - unInstall(): same pattern public function unInstall(array $params): bool { // ... $path = BASE_PATH . '/plugin/' . $params['identifier']; // Path traversal Plugin::uninstall($params['identifier']); // Arbitrary uninstall return true; } ``` **File:** `plugin/mine-admin/app-store/src/Controller/IndexController.php` (lines 25-26) ```php #[Controller(prefix: 'admin/plugin/store')] #[Middleware(middleware: AccessTokenMiddleware::class, priority: 100)] // Only AccessTokenMiddleware -- no PermissionMiddleware (see GM-4340) ``` ### Proof of Concept ```bash # Install a "plugin" from a traversed path, potentially triggering composer on # arbitrary directories curl -X POST "http://localhost:9501/admin/plugin/store/install" \ -H "Authorization: Bearer <JWT_TOKEN>" \ -H "Content-Type: application/json" \ -d '{"identifier": "../app", "version": "1.0.0"}' # This resolves to BASE_PATH/plugin/../app = BASE_PATH/app # Plugin::install("../app") processes the application directory as a plugin # Check if arbitrary path exists: curl -X POST "http://localhost:9501/admin/plugin/store/download" \ -H "Authorization: Bearer <JWT_TOKEN>" \ -H "Content-Type: application/json" \ -d '{"identifier": "../../etc", "version": "1.0.0"}' ``` ### Impact - Path traversal enables reading directory existence outside the plugin directory - `Plugin::install()` with a traversed identifier may run composer commands on arbitrary directories - Combined with GM-4340 (missing PermissionMiddleware), any authenticated user can exploit this - Could lead to arbitrary code execution depending on `Plugin::install()` implementation ### Remediation Validate and sanitize the `identifier` parameter to reject path traversal sequences. Use `basename()` or a strict regex allowlist (e.g., `^[a-zA-Z0-9_-]+$`) before concatenating into file paths.\n\n---\n\n**Update:** This finding has now been fully reproduced and validated in a Docker environment. The vulnerability is confirmed exploitable as described in the original report.
来源: GitHub Advisory · Provisional
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
来源: GitHub Advisory · Provisional
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: GitHub Advisory · Provisional

受影响产品

厂商 产品 影响版本 CPE 订阅
mineadmin mineadmin/mineadmin < 3.2.0-alpha.2 ~ 3.2.0-alpha.2 -

二、漏洞 CVE-2026-55224 的公开POC

# POC 描述 源链接 神龙链接
1 MineAdmin versions before 3.2.0-alpha.2 contain a path traversal vulnerability in the app-store plugin service. The identifier parameter is concatenated into filesystem paths without sanitization. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-55224.yaml POC详情
在正式 CVE 记录发布前,不启动 AI POC 生成;上方仍保留已核验的公开 PoC 索引。

三、漏洞 CVE-2026-55224 的情报信息

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-55224

暂无评论


发表评论