High severity7.5NVD Advisory· Published Oct 11, 2026
CVE-2026-108739
CVE-2026-108739
Description
OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.
Affected products
2<=1.0.17+ 1 more
- (no CPE)range: <=1.0.17
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.pynvd
- github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.pynvd
- hackmd.io/@haind/openagents-workspace-list-browserfabric-key-disclosurenvd
- www.vulncheck.com/advisories/openagents-workspace-through-launcher-1.0.17-unauthenticated-credential-exposure-via-v1-workspacesnvd
News mentions
0No linked articles in our index yet.