Impact
Soft Machine's workspace HTTP service listens on all interfaces on port 8080 and exposes several endpoints without authentication. These endpoints allow any host that can reach the service to read arbitrary files under the workspace root or download entire project directories as tar archives. The lack of an authentication mechanism means that the confidentiality of the workspace data is compromised, and attackers can exfiltrate sensitive source code or configuration files.
Affected Systems
The problem exists in all releases of Soft Machine that embed the sm-ws-* workspace agents, specifically those with version 0.2.247 and prior. Every workspace runs on the same Fly private 6PN and discovers other peers through an unauthenticated TXT record, allowing any sm‑ws‑* instance in the same Fly application or organization to reach the vulnerable service.
Risk and Exploitability
The CVSS base score of 8.3 reflects a high impact, and because the EPSS score is not available the probability of exploitation is unknown but potentially significant in environments where the internal network is not segregated. The vulnerability is classified as CWE‑306 (Missing Authentication). Attackers only need network connectivity to the workspace port 8080 and can abuse the exposed endpoints to read files or download the entire workspace. The vulnerability is not listed in CISA KEV, but it could be weaponized in targeted incidents.
OpenCVE Enrichment