GHSA-7f7m-83r3-p644

Suggest an improvement
Source
https://github.com/advisories/GHSA-7f7m-83r3-p644
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-7f7m-83r3-p644/GHSA-7f7m-83r3-p644.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7f7m-83r3-p644
Aliases
  • CVE-2026-1194
Published
2026-01-20T00:30:27Z
Modified
2026-02-05T22:41:42.274693Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Details

A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-05T22:00:45Z",
    "nvd_published_at": "2026-01-20T00:15:48Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / mineadmin/mineadmin

Package

Name
mineadmin/mineadmin
Purl
pkg:composer/mineadmin/mineadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Last affected
2.0.3

Affected versions

v1.*
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.*
v2.0-stable
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
2.*
2.0.0-alpha.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-7f7m-83r3-p644/GHSA-7f7m-83r3-p644.json"