VYPR

honcho

by Plastic Labs

CVEs (1)

  • CVE-2026-108711MedOct 11, 2026
    risk 0.21cvss 4.3epss —

    Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the…