PT-2026-109731 · Innocommerce · Innoshop

·

CVE-2026-108591

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files create permission to read server files by abusing the AI Core MCP file upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file get contents(), storing contents on the public media disk to expose the .env file with APP KEY and database credentials.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108591

Affected Products

Innoshop