CVE-2026-108582

MEDIUMCVSS 5.5/10

Last modified

CVE-2026-108582 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token..

Description

GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
genspark-aiGenOffice<= 0.11.505

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-108582?
GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token.
How severe is CVE-2026-108582?
CVE-2026-108582 has a CVSS score of 5.5/10 (MEDIUM severity).
How do I fix CVE-2026-108582?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-108582?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST