Description
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.
Published: 2026-09-30
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Information Disclosure through Unauthenticated File Read and Directory Exfiltration
Action: Apply Patch
AI Analysis

Impact

Soft Machine's workspace HTTP service listens on all interfaces on port 8080 and exposes several endpoints without authentication. These endpoints allow any host that can reach the service to read arbitrary files under the workspace root or download entire project directories as tar archives. The lack of an authentication mechanism means that the confidentiality of the workspace data is compromised, and attackers can exfiltrate sensitive source code or configuration files.

Affected Systems

The problem exists in all releases of Soft Machine that embed the sm-ws-* workspace agents, specifically those with version 0.2.247 and prior. Every workspace runs on the same Fly private 6PN and discovers other peers through an unauthenticated TXT record, allowing any sm‑ws‑* instance in the same Fly application or organization to reach the vulnerable service.

Risk and Exploitability

The CVSS base score of 8.3 reflects a high impact, and because the EPSS score is not available the probability of exploitation is unknown but potentially significant in environments where the internal network is not segregated. The vulnerability is classified as CWE‑306 (Missing Authentication). Attackers only need network connectivity to the workspace port 8080 and can abuse the exposed endpoints to read files or download the entire workspace. The vulnerability is not listed in CISA KEV, but it could be weaponized in targeted incidents.

Generated by OpenCVE AI on September 30, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Soft Machine to a release newer than 0.2.247 once a vendor patch is available.
  • Block TCP port 8080 on the workspace network for non‑trusted hosts using firewall rules or security groups.
  • Disable the unauthenticated peer discovery or isolate workspaces by moving them to segregated Fly private networks that do not expose the _instances.internal TXT record to other org members.

Generated by OpenCVE AI on September 30, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.
Title Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T17:02:21.234Z

Reserved: 2026-05-15T23:26:58.309Z

Link: CVE-2026-46711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T17:16:46.060

Modified: 2026-09-30T17:16:46.060

Link: CVE-2026-46711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function