CVE-2026-108591: InnoShop 0.9.2 Local File Disclosure via AI Core MCP file_upload Tool
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with filescreate permission to read server files by abusing the AI Core MCP fileupload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to filegetcontents(), storing contents on the public media disk to expose the .env file with APPKEY and database credentials.
Affected Software
Event History
Frequently Asked Questions
Which accounts are exposed to this issue?
An attacker must be authenticated as an administrator and have the files_create permission. Unauthenticated users and accounts without that permission are not described as able to exploit it.
What does exploitation require?
The attacker needs to invoke the AI Core MCP file_upload tool and control its source argument. Exploitation relies on supplying a file:// or php:// stream wrapper that is read through file_get_contents().
What data could be disclosed?
The described impact includes reading server-local files and placing their contents on the public media disk. The .env file is specifically identified, which may expose the APP_KEY and database credentials.