Product
An information disclosure vulnerability in the OpenAgents Workspace backend allows unauthenticated attackers to exfiltrate workspace metadata and API keys via the /v1/workspaces endpoint.