mineadmin/mineadmin
Quickly build a background management system for web applications
Activity
- Latest release
- 1mo ago
- Total releases
- 47
- Cadence
- ~14 days
- Last 12 months
- 3
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Apr 07, 2022
| Version | Released | |
|---|---|---|
v3.2.0
minor
|
v3.2.0
minor
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
v3.2.0-alpha.2
pre
| ||
v3.2.0-alpha.1
pre
1 CVE
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev | ||
v3.0.9
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.8
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.7
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.6
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.5
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.4
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.3
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.2
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.1
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0
major
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0-RC
pre
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.3
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.2
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.1.1
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.1
major
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.0.1
major
Dependencies (8)
Changelog
Compare changes
|
|
v2.0-RC.1
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta.6
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.0.0-beta.6
pre
Dependencies (8)
Changelog
Compare changes
|
|
v2.0.0-beta.5
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta.4
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta.3
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta.2
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta.1
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-beta
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.0.0-beta
pre
Dependencies (7)
Changelog
Compare changes
|
|
v1.4.13
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.4.12
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.4.11
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-alpha.5
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.4.1
minor
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-alpha.4
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0-alpha.3
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.0.0-alpha.3
pre
Dependencies (7)
Changelog
Compare changes
|
|
v2.0.0-alpha.2
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-alpha.1
pre
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.3.3
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.3.0
minor
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.2.1
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.2.0
minor
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.1.1
patch
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.1.0
minor
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0
major
6 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-1195
GHSA-43rr-x62x-q96w
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
Network
High
Low
None
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1196
GHSA-wq8p-q8cq-94w5
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
Network
High
Low
None
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1194
GHSA-7f7m-83r3-p644
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Medium
Network
Low
None
None
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-1193
GHSA-23hh-2f47-3p4h
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
Network
Low
Low
None
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
2.0.0-alpha.1
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
+ 16 more Show less
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v0.7.2
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v0.7.1
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v0.7.0
minor
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v0.6.3
patch
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v0.6.2
initial
2 CVEs
CVE-2026-55224
GHSA-59xm-4m8c-g3xj
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
Network
Low
None
None
Path Traversal via Unsanitized Identifier in Plugin Install/UninstallSummaryThe app-store plugin service concatenates unsanitized user-supplied Vulnerable CodeFile:
File:
Proof of Concept
Impact
RemediationValidate and sanitize the Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 33 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.2.0-alpha.1
Fixed in
3.2.0-alpha.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2025-65854
GHSA-x6mh-4w8x-p34v
Dec 12, 2025
MineAdmin has an insecure default password
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. Affected versions
2.0.0-alpha.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
+ 32 more Show less
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
v3.0
v3.0-RC
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |