PatchSiren

innocommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM innocommerce CVE published 2026-10-10

CVE-2026-108591

CVE-2026-108591 debrief based on 7 source links from [email protected] and NIST NVD. InnoShop 0.9.2 has a local file disclosure vulnerability via AI Core MCP file_upload tool. The vulnerability allows authenticated administrators with files_create permission to read server files, potentially exposing sensitive information. Defenders should assess exposure, verify inventory, and monitor for potentia [truncated]