Description
Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Information Disclosure
Action: Apply Workaround
AI Analysis

Impact

The vulnerability stems from an Incorrect Authorization (CWE-863) flaw that permits peer‑ or session‑scoped API key holders to call the POST /v3/workspaces endpoint with a parent workspace name. The get_or_create_workspace routine verifies only the workspace claim, ignoring the owner's scope, which leads to the disclosure of workspace metadata and configuration such as custom_instructions that should be restricted to workspace or admin keys. This flaw facilitates the theft of sensitive configuration data without requiring privileged credentials.

Affected Systems

Plastic Labs Honcho version 3.3.0 and earlier. The affected product is the Honcho API server hosted by Plastic Labs. Versions newer than 3.3.0 are presumed fixed, but the exact upstream fix version is not listed in the data.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently known to be exploited in the wild. The attack vector is likely remote, requiring the ability to send HTTP requests to the API and possession of a peer‑ or session‑scoped API key. Once the key is in hand, the attacker can send a crafted payload to POST /v3/workspaces and retrieve confidential workspace details, creating a moderate risk of data exposure so long as the API key can be obtained by adversaries.

Generated by OpenCVE AI on October 11, 2026 at 14:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest release of Plastic Labs Honcho (>=3.3.1) when available.
  • Enforce stricter role‑based access controls so that peer‑ and session‑scoped keys cannot retrieve workspace metadata, ensuring that only workspace or admin scopes have that privilege.
  • Implement a temporary rule that blocks the POST /v3/workspaces endpoint for non‑admin or non‑workspace‑scoped keys and rejects requests containing parent workspace names that the caller is not authorized to access, mitigating the CWE‑863 exploit.

Generated by OpenCVE AI on October 11, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.
Title Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:25.400Z

Reserved: 2026-10-11T01:51:09.941Z

Link: CVE-2026-108711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:13.877

Modified: 2026-10-11T13:17:13.877

Link: CVE-2026-108711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses