Description
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.
Published: 2026-09-30
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized cross-tenant API access
Action: Assess Impact
AI Analysis

Impact

Soft Machine versions 0.2.247 and earlier contain an authentication flaw in server.js where the global CONTAINER_SHARED_SECRET can be supplied as a bearer token. The verification helpers do not confirm the caller’s workspace, allowing any tenant to use the same secret to authenticate against another tenant’s workspace API. This bypass grants unauthorized read, write, and destructive‑restore capabilities across workspaces, effectively enabling cross‑tenant privilege escalation and data tampering.

Affected Systems

The affected vendor is Soft‑Machine‑io and its security component. Any instance of Soft Machine running version 0.2.247 or earlier is vulnerable. No specific product sub‑versions are listed beyond this threshold, and the vulnerability applies to the shared‑secret bearer token path used by the workspace API. Only the global security module is impacted.

Risk and Exploitability

With a CVSS score of 9, the vulnerability is considered critical. The EPSS score is not available, but the lack of a publicly known patch and the ability for any tenant’s shell to acquire the shared secret make exploitation plausible. Because the shared secret is propagated to all containers and exposed in the user‑facing process environment, an attacker with tenant access can trivially construct a request to the API using the bearer token, bypassing per‑workspace token checks. The vulnerability is not yet listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 30, 2026 at 20:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version newer than 0.2.247 that removes the shared‑secret bearer token usage, or apply a vendor‑issued patch when released.
  • Temporarily rotate or revoke the CONTAINER_SHARED_SECRET in all running containers to invalidate the shared bearer token until a fix is available.
  • Enforce stricter network controls by isolating tenant API endpoints from tenant shells, and monitor API usage for unusual cross‑workspace activity.

Generated by OpenCVE AI on September 30, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Soft-machine-io
Soft-machine-io security
Vendors & Products Soft-machine-io
Soft-machine-io security

Wed, 30 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.
Title Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Soft-machine-io Security
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T16:30:42.729Z

Reserved: 2026-06-16T15:20:43.085Z

Link: CVE-2026-55176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T17:16:46.630

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-55176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:30:05Z

Weaknesses