CVE-2026-48787
flipped-aurora gin-vue-admin
gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulnerability by injecting attacker-controlled Go source code through POST /autoCode/addFunc, and then invoking POST /autoCode/mcpStart to trigger a rebuild and restart of the standalone MCP service. This allows arbitrary operating system commands to be executed on the server with the privileges of the application process. Successful exploitation may lead to remote code execution (RCE), modification o...
- CVSS
- 7.4
- EPSS
- 0.69% 49.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.20