Medium severity4.4NVD Advisory· Published Oct 10, 2026
CVE-2026-108591
CVE-2026-108591
Description
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials.
Affected products
1- Range: <0.9.2
Patches
Vulnerability mechanics
References
4- github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/aicore/src/Tools/FileUploadTool.phpnvd
- github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/restapi/src/Services/UploadService.phpnvd
- hackmd.io/@haind/innoshop-mcp-local-file-readnvd
- www.vulncheck.com/advisories/innoshop-0.9.2-local-file-disclosure-via-ai-core-mcp-file-upload-toolnvd
News mentions
0No linked articles in our index yet.