
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55224 is a path traversal vulnerability in MineAdmin's app-store plugin service that allows attackers to read, install, or uninstall plugins from arbitrary directories and potentially execute arbitrary Composer commands. It affects all versions of the mineadmin/mineadmin Composer package prior to 3.2.0-alpha.2. The vulnerability was originally reported on June 11, 2026, and published to the GitHub Advisory Database on August 18, 2026. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where the download(), install(), and unInstall() methods in plugin/mine-admin/app-store/src/Service/Service.php concatenate the user-supplied identifier parameter directly into file system paths without sanitization (e.g., BASE_PATH . '/plugin/' . $params['identifier']). An attacker can supply traversal sequences such as ../ to escape the intended /plugin/ directory and reference arbitrary paths on the server. Compounding the issue, the IndexController controlling these endpoints applied only AccessTokenMiddleware and lacked PermissionMiddleware, meaning any authenticated user — regardless of role — could reach the vulnerable endpoints (GitHub Advisory, MineAdmin Security Advisory).
Successful exploitation allows an authenticated attacker to install or uninstall plugins from arbitrary directories on the server, probe directory existence outside the plugin root, and potentially trigger Plugin::install() with a traversal path — which may execute Composer commands against arbitrary directories, leading to arbitrary code execution with the privileges of the application process. The integrity of the vulnerable system is the primary concern, as an attacker could manipulate application files or introduce malicious code. Combined with the missing PermissionMiddleware, the attack surface extends to any user holding a valid access token, not just administrators (GitHub Advisory, MineAdmin Security Advisory).
The vulnerability requires a valid access token (authenticated user) but no special permissions, making it exploitable by any logged-in user. A proof-of-concept using curl is included in the public advisory, demonstrating exploitation via crafted JSON payloads to the /admin/plugin/store/install and /admin/plugin/store/download endpoints. A Nuclei detection template was added to the ProjectDiscovery nuclei-templates repository (commit f37500939bfe9d94f69d1070537ded4fa6a9a070, included in release v10.4.8), further lowering the barrier to exploitation. As of the advisory publication date, there is no confirmed evidence of in-the-wild exploitation, and the CVE status remains Reserved. No EPSS score or CISA KEV listing is currently available (GitHub Advisory, Nuclei Templates).
PermissionMiddleware.curl -X POST "http://<target>:9501/admin/plugin/store/download" \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{"identifier": "../../etc", "version": "1.0.0"}'The server resolves this to BASE_PATH/plugin/../../etc, revealing directory existence via response differences.curl -X POST "http://<target>:9501/admin/plugin/store/install" \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{"identifier": "../app", "version": "1.0.0"}'This resolves to BASE_PATH/plugin/../app = BASE_PATH/app, causing Plugin::install("../app") to process the application directory as a plugin.Plugin::install() runs Composer commands against the traversed directory, an attacker who can influence composer.json in that directory (or who targets a directory with a malicious composer.json) can achieve arbitrary code execution with the privileges of the web application process (GitHub Advisory, MineAdmin Security Advisory)./admin/plugin/store/install, /admin/plugin/store/uninstall, or /admin/plugin/store/download containing ../ or URL-encoded traversal sequences (e.g., %2e%2e%2f) in the identifier JSON field.identifier values containing path separators or traversal patterns; repeated requests from a single authenticated user probing different traversal depths.install.lock files appearing outside the /plugin/ directory; new or modified files in application directories (e.g., BASE_PATH/app/) that correspond to plugin installation artifacts.composer child processes spawned by the PHP/web application process, particularly targeting directories outside the designated plugin path.Upgrade to MineAdmin version 3.2.0-alpha.2 or later, which introduces a normalizeIdentifier() method that validates the identifier parameter against a strict allowlist regex (/\A[A-Za-z0-9_-]+\/[A-Za-z0-9_-]+\z/) before any file system operations, and adds PermissionMiddleware and a plugin:store permission check to the IndexController (MineAdmin Release, Patch Commit). As a temporary workaround for those unable to upgrade immediately, restrict access to the /admin/plugin/store/* endpoints at the network or reverse-proxy level to trusted administrator IP addresses only. Additionally, ensure that the application process runs with the minimum necessary file system privileges to limit the impact of any traversal exploitation.
A technical blog post covering CVE-2026-55224 alongside other unauthenticated infrastructure vulnerabilities was published by security researcher Deniz Halil on August 20, 2026, and referenced again in a broader roundup on August 24, 2026 (Deniz Halil Blog). The vulnerability was also picked up by Tenable's cloud security plugin catalog and by the ProjectDiscovery Nuclei templates project, indicating moderate community interest in detection coverage (Nuclei Templates).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."