Description
OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.
Published: 2026-10-11
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Sensitive data disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability in OpenAgents Workspace backend version 1.0.17 allows an unauthenticated attacker to send a GET request to the /v1/workspaces endpoint and receive a full list of workspaces. The response includes the unmasked browserfabric_api_key for each workspace, as well as workspace identifiers, slugs, creator emails, and member lists, exposing sensitive configuration and identifying information.

Affected Systems

The issue affects the OpenAgents Workspace backend, version 1.0.17, released by openagents‑org. No other versions or products are listed as affected in the available data.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, placing it in the high severity range. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Because the endpoint can be accessed without authentication, any external user with network connectivity to the service can extract the exposed data. The exploit requires only a standard network connection and does not depend on additional configuration or privileged access.

Generated by OpenCVE AI on October 11, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAgents to a patched release in which the /v1/workspaces endpoint no longer reveals unmasked API keys, such as launcher v1.0.18 or later.
  • Configure the backend to require authentication and appropriate role‑based permissions before allowing access to the /v1/workspaces endpoint.
  • Modify the application code or configuration to strip or mask sensitive fields, such as browserfabric_api_key, from API responses before they are returned to the client.

Generated by OpenCVE AI on October 11, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openagents-org
Openagents-org openagents
Vendors & Products Openagents-org
Openagents-org openagents

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.
Title OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1/workspaces
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openagents-org Openagents
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:44.257Z

Reserved: 2026-10-11T01:52:54.688Z

Link: CVE-2026-108739

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:18.383

Modified: 2026-10-11T13:17:18.383

Link: CVE-2026-108739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function