GHSA-93ww-wv4j-3wjqMediumCVSS 4.4
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated...
🔗 CVE IDs covered (1)
📋 Description
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-108591
- https://github.com/innocommerce/innoshop
- https://github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/aicore/src/Tools/FileUploadTool.php#L55-L89
- https://github.com/innocommerce/innoshop/blob/6af6a9744414d10d2f5aab516ed0b6c3045a2848/innopacks/restapi/src/Services/UploadService.php#L33
- https://hackmd.io/@haind/innoshop-mcp-local-file-read
- https://www.vulncheck.com/advisories/innoshop-0.9.2-local-file-disclosure-via-ai-core-mcp-file-upload-tool
- https://github.com/advisories/GHSA-93ww-wv4j-3wjq