{"id":"GHSA-x6mh-4w8x-p34v","summary":"MineAdmin has an insecure default password","details":"Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.","aliases":["CVE-2025-65854"],"modified":"2026-09-10T03:50:32.279596109Z","published":"2025-12-12T18:30:35Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-12-12T22:13:22Z","nvd_published_at":"2025-12-12T16:15:44Z","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65854"},{"type":"WEB","url":"https://gist.github.com/SourByte05/1a6c6b08ac47c5d58eb7dd4422cc23b7"},{"type":"WEB","url":"https://github.com/mineadmin/mine-core/blob/7994da7f5cd0778eb9aadd550c50c259cc1d1048/src/Command/InstallProjectCommand.php#L123"},{"type":"PACKAGE","url":"https://github.com/mineadmin/mineadmin"},{"type":"WEB","url":"http://mineadmin.com"}],"affected":[{"package":{"name":"mineadmin/mineadmin","ecosystem":"Packagist","purl":"pkg:composer/mineadmin/mineadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.9"}]}],"versions":["2.0.0-alpha.1","v0.6.2","v0.6.3","v0.7.0","v0.7.1","v0.7.2","v1.0.0","v1.1.0","v1.1.1","v1.2.0","v1.2.1","v1.3.0","v1.3.3","v1.4.1","v1.4.11","v1.4.12","v1.4.13","v2.0-RC.1","v2.0.0-alpha.2","v2.0.0-alpha.3","v2.0.0-alpha.4","v2.0.0-alpha.5","v2.0.0-beta","v2.0.0-beta.1","v2.0.0-beta.2","v2.0.0-beta.3","v2.0.0-beta.4","v2.0.0-beta.5","v2.0.0-beta.6","v2.0.1","v2.0.1.1","v2.0.2","v2.0.3","v3.0","v3.0-RC","v3.0.1","v3.0.2","v3.0.3","v3.0.4","v3.0.5","v3.0.6","v3.0.7","v3.0.8","v3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-x6mh-4w8x-p34v/GHSA-x6mh-4w8x-p34v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}