CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108591

MEDIUMCVSS 4.4NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents()

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108591 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108591

MEDIUMCVSS 4.4NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents()

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]