CVE-2026-55224: MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
The app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55224 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →