Impact
The vulnerability in OpenAgents Workspace backend version 1.0.17 allows an unauthenticated attacker to send a GET request to the /v1/workspaces endpoint and receive a full list of workspaces. The response includes the unmasked browserfabric_api_key for each workspace, as well as workspace identifiers, slugs, creator emails, and member lists, exposing sensitive configuration and identifying information.
Affected Systems
The issue affects the OpenAgents Workspace backend, version 1.0.17, released by openagents‑org. No other versions or products are listed as affected in the available data.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, placing it in the high severity range. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Because the endpoint can be accessed without authentication, any external user with network connectivity to the service can extract the exposed data. The exploit requires only a standard network connection and does not depend on additional configuration or privileged access.
OpenCVE Enrichment