CVE-2026-22786

HIGH

Flipped-aurora Gin-vue-admin - Path Traversal

Title source: rule
STIX 2.1

Description

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile function accepts a fileName parameter through the /fileUploadAndDownload/breakpointContinueFinish API endpoint and directly concatenates it with the base directory path (./fileDir/) using os.OpenFile() without any validation for directory traversal sequences (e.g., ../). An attacker with file upload privileges could exploit this vulnerability.

Scores

CVSS v3 7.2
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-434
Status published
Products (2)
flipped-aurora/gin-vue-admin 0Go
gin-vue-admin_project/gin-vue-admin < 2.8.7
Published Jan 12, 2026
Tracked Since Feb 18, 2026