Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108711
CVE-2026-108711
Description
Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.
Affected products
1- Range: <=3.3.0
Patches
Vulnerability mechanics
References
5- github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/crud/workspace.pynvd
- github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/routers/workspaces.pynvd
- github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/security.pynvd
- hackmd.io/@haind/honcho-scoped-jwt-workspace-config-disclosurenvd
- www.vulncheck.com/advisories/plastic-labs-honcho-through-3.3.0-incorrect-authorization-via-post-v3-workspacesnvd
News mentions
0No linked articles in our index yet.