MEDIUM
innocommerce
CVE published 2026-10-10
CVE-2026-108591
CVE-2026-108591 debrief based on 7 source links from [email protected] and NIST NVD. InnoShop 0.9.2 has a local file disclosure vulnerability via AI Core MCP file_upload tool. The vulnerability allows authenticated administrators with files_create permission to read server files, potentially exposing sensitive information. Defenders should assess exposure, verify inventory, and monitor for potentia [truncated]