Sceawere
Vulnerability Detail
CVE-2026-108582UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GenOffice Insecure File Permissions
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 2h ago
- Vendor
- genspark-ai
- Product
- GenOffice
- Attack Type
- Incorrect Permission Assignment for Critical Resource
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-10T16:16:31.520Z",
"pubdate": "2026-10-10T16:16:31.520Z",
"executiveSummary": "GenOffice versions up to and including 0.11.505 contain a critical incorrect permissions vulnerability within its HTTP MCP server file store. The vulnerability stems from the application creating a directory with world-readable permissions under the system's temporary directory, specifically the 'genoffice-mcp-http' folder.\nThis design flaw allows any local unprivileged user on the host system to bypass established HTTP bearer token authentication mechanisms. By navigating to the exposed directory, an attacker can list and access sensitive uploaded documents and converted output files generated by the service.\nThe impact is significant, leading to a complete breach of confidentiality for user-processed data. Because the directory is world-readable, the vulnerability does not require administrative privileges or specialized network access; exploitation is strictly a local privilege escalation or information disclosure vector. Organizations utilizing this version of GenOffice are at risk of data exfiltration by unauthorized users sharing the same host environment, necessitating immediate configuration changes or updates to secure the underlying file system permissions.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure handling of the file system during the initialization of the HTTP MCP (Model Context Protocol) server. When GenOffice handles file-based operations, it creates a dedicated storage directory, 'genoffice-mcp-http', within the operating system's temporary file path (e.g., /tmp or equivalent). The application fails to apply restrictive POSIX file permissions (such as 0700 or 0750) upon the creation of this directory.\nInstead, the directory is initialized with world-readable permissions. In a multi-user environment, this behavior grants every local user account read access to the directory contents, effectively rendering the HTTP bearer token security control moot. The MCP server processes sensitive client uploads and generates document outputs, storing them in this insecure directory as plaintext or raw data files.\nThe attack flow is straightforward and does not require complex exploitation techniques. An attacker with a low-privilege local shell account can perform the following steps: 1) Identify the system temporary directory utilized by the GenOffice service. 2) List the contents of the 'genoffice-mcp-http' directory, which is immediately accessible due to the permissive file mode. 3) Enumerate, read, and exfiltrate any files currently residing in the directory, including client-submitted uploads and the resulting converted documents. 4) Continuously monitor the directory for new file arrivals to intercept data in real-time.\nThis vulnerability is classified as an Incorrect Permission Assignment (CWE-276). Because the vulnerability resides at the file system level rather than the application logic level, it bypasses all application-layer authentication and authorization checks. The MCP protocol, intended to facilitate secure communication between Large Language Models and local file tools, fails to maintain the necessary isolation between host users. Consequently, any data handled by the GenOffice MCP server is implicitly exposed to all local system users for the entire lifecycle of the file. The threat persists as long as the application process retains default file creation mask (umask) settings that do not explicitly override system-wide permissive defaults, ensuring that even temporary files inherit the vulnerable access control list."
}