CVE-2026-108711
Description
Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/plastic-labs/honcho
- https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/crud/workspace.py#L112-L119
- https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/routers/workspaces.py#L41-L72
- https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/security.py#L218-L225
- https://hackmd.io/@haind/honcho-scoped-jwt-workspace-config-disclosure
- https://www.vulncheck.com/advisories/plastic-labs-honcho-through-3.3.0-incorrect-authorization-via-post-v3-workspaces
CWEs
CWE-863
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.