PatchSiren

genspark-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM genspark-ai CVE published 2026-10-10

CVE-2026-108582

CVE-2026-108582 is a medium-severity vulnerability in GenOffice through version 0.11.505. This vulnerability allows local unprivileged users to read uploaded and generated documents due to incorrect permissions in its HTTP MCP server file store. The vulnerability can be exploited by listing the world-readable genoffice-mcp-http directory under the system temporary directory, bypassing the HTTP bearer toke [truncated]