{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/workspace--launcher-v1.0.17/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openagents:workspace:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108739"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Workspace (\u003c= launcher-v1.0.17)"],"_cs_severities":["high"],"_cs_tags":["information-disclosure","api-security","cloud"],"_cs_type":"advisory","_cs_vendors":["OpenAgents"],"content_html":"\u003cp\u003eThe OpenAgents Workspace backend, specifically versions through launcher-v1.0.17, contains a critical information disclosure vulnerability. This flaw resides in the /v1/workspaces API endpoint, which fails to properly authenticate requests. An unauthenticated remote attacker can issue a GET request to this endpoint to retrieve a comprehensive list of all workspaces within an organization's deployment. The response includes sensitive information such as internal workspace identifiers, URL slugs, lists of member email addresses, and the unmasked 'browserfabric_api_key'. Access to these API keys poses a significant risk of further exploitation, as they may be used to access external services or manipulate the underlying browser infrastructure associated with those workspaces. This vulnerability was identified as CVE-2026-108739.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized mass exfiltration of organizational structure, internal user email addresses, and active API credentials. Exposure of the 'browserfabric_api_key' effectively grants an attacker the ability to hijack existing browser sessions or interact with the platform as an authenticated user, potentially leading to data theft or further unauthorized access to integrated systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize immediate patching of the OpenAgents Workspace backend. Upgrade all instances running version 1.0.17 or earlier to the latest secure version released by the vendor that addresses CVE-2026-108739. If immediate patching is not possible, implement a temporary restriction on external access to the /v1/workspaces API endpoint at the reverse proxy or WAF layer for all unauthenticated traffic.\u003c/p\u003e\n","date_modified":"2026-10-11T14:01:26Z","date_published":"2026-10-11T14:01:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-openagents-info-disclosure/","summary":"An information disclosure vulnerability in the OpenAgents Workspace backend allows unauthenticated attackers to exfiltrate workspace metadata and API keys via the /v1/workspaces endpoint.","title":"Information Disclosure Vulnerability in OpenAgents Workspace","url":"https://feed.craftedsignal.io/briefs/2026-10-openagents-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Workspace (\u003c= Launcher-V1.0.17)","version":"https://jsonfeed.org/version/1.1"}