Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

gin-vue-admin 2.9.1 code-generation/MCP flaw allows remote code execution (CVE-2026-48787)

An authenticated attacker with access to the code-generation feature and MCP management interface of gin-vue-admin 2.9.1 can inject Go source code via POST /autoCode/addFunc and trigger a rebuild/restart via POST /autoCode/mcpStart, executing arbitrary OS commands with the application's privileges. Impacts include remote code execution, backdoor persistence and manipulation of application data and configuration; no patched version was known at publication.

Disclosed 19 June 2026 · Record updated 13 September 2026

Impact

Potential remote code execution on the server with application process privileges, modification of backend source code or runtime logic, deployment of persistent backdoors, and access to or manipulation of application data and configuration.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48787