CVE-2026-108591
InnoShop 0.9.2 Local File Disclosure via AI Core MCP file_upload Tool
CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials.
| CWE | CWE-73 |
| Vendor | innocommerce |
| Product | innoshop |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for innocommerce innoshop
Be the first to know when new medium vulnerabilities affecting innocommerce innoshop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
innocommerce / InnoShop
0.9.2 โค 0.9.2
References
hackmd.io: https://hackmd.io/@haind/innoshop-mcp-local-file-read github.com: https://github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/aicore/src/Tools/FileUploadTool.php#L55-L89 github.com: https://github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/restapi/src/Services/UploadService.php#L33 github.com: https://github.com/innocommerce/innoshop vulncheck.com: https://www.vulncheck.com/advisories/innoshop-0.9.2-local-file-disclosure-via-ai-core-mcp-file-upload-tool
Credits
HaiND from the Post and Telecommunication Institute of Technology