What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). A filesystem-permission failure in an MCP document-processing server's temp store.
Why it matters
MCP servers handle sensitive data (documents handled by AI); a misconfigured temp dir defeats the transport auth boundary for local attackers on the same host.
Attack vector
The MCP file store is created with world-readable permissions under the system temp dir, so any local user lists it to read client uploads and converted outputs the HTTP token was meant to protect (CWE-732).
Affected systems
genspark-ai/genoffice <= 0.11.505 (packages/cli/src/mcp/files.ts)
Mitigation
Upgrade past 0.11.505; create the file store with owner-only permissions and clean up temp artifacts. See VulnCheck advisory.