What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). Admin-scoped local file disclosure through an AI Core MCP tool.
Why it matters
MCP tools wired into platforms get access to file primitives; a stream-wrapper path turns an AI file-upload tool into a server file-read primitive exposing application secrets.
Attack vector
The file_upload source argument is passed to file_get_contents() with file:// or php:// stream wrappers, storing server-file contents on the public media disk to expose .env with APP_KEY and database credentials (CWE-73).
Affected systems
innocommerce/innoshop 0.9.2 (AI Core MCP FileUploadTool)
Mitigation
Update InnoShop; validate that the MCP upload source is a real local file path (no stream wrappers) and never store to the public media disk. See VulnCheck advisory.