MEDIUM
genspark-ai
CVE published 2026-10-10
CVE-2026-108582
CVE-2026-108582 is a medium-severity vulnerability in GenOffice through version 0.11.505. This vulnerability allows local unprivileged users to read uploaded and generated documents due to incorrect permissions in its HTTP MCP server file store. The vulnerability can be exploited by listing the world-readable genoffice-mcp-http directory under the system temporary directory, bypassing the HTTP bearer toke [truncated]