Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials. | |
| Title | InnoShop 0.9.2 Local File Disclosure via AI Core MCP file_upload Tool | |
| Weaknesses | CWE-73 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T18:16:55.939Z
Reserved: 2026-10-10T18:08:11.062Z
Link: CVE-2026-108591
No data.
No data.
No data.
OpenCVE Enrichment
No data.