CVE-2026-108739
Description
OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/openagents-org/openagents
- https://github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.py#L135-L177
- https://github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.py#L326-L349
- https://hackmd.io/@haind/openagents-workspace-list-browserfabric-key-disclosure
- https://www.vulncheck.com/advisories/openagents-workspace-through-launcher-1.0.17-unauthenticated-credential-exposure-via-v1-workspaces
CWEs
CWE-306
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.