<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenAgents - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/openagents/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/openagents/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in OpenAgents Workspace</title><link>https://feed.craftedsignal.io/briefs/2026-10-openagents-info-disclosure/</link><pubDate>Sun, 11 Oct 2026 14:01:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-openagents-info-disclosure/</guid><description>An information disclosure vulnerability in the OpenAgents Workspace backend allows unauthenticated attackers to exfiltrate workspace metadata and API keys via the /v1/workspaces endpoint.</description><content:encoded><![CDATA[<p>The OpenAgents Workspace backend, specifically versions through launcher-v1.0.17, contains a critical information disclosure vulnerability. This flaw resides in the /v1/workspaces API endpoint, which fails to properly authenticate requests. An unauthenticated remote attacker can issue a GET request to this endpoint to retrieve a comprehensive list of all workspaces within an organization's deployment. The response includes sensitive information such as internal workspace identifiers, URL slugs, lists of member email addresses, and the unmasked 'browserfabric_api_key'. Access to these API keys poses a significant risk of further exploitation, as they may be used to access external services or manipulate the underlying browser infrastructure associated with those workspaces. This vulnerability was identified as CVE-2026-108739.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized mass exfiltration of organizational structure, internal user email addresses, and active API credentials. Exposure of the 'browserfabric_api_key' effectively grants an attacker the ability to hijack existing browser sessions or interact with the platform as an authenticated user, potentially leading to data theft or further unauthorized access to integrated systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize immediate patching of the OpenAgents Workspace backend. Upgrade all instances running version 1.0.17 or earlier to the latest secure version released by the vendor that addresses CVE-2026-108739. If immediate patching is not possible, implement a temporary restriction on external access to the /v1/workspaces API endpoint at the reverse proxy or WAF layer for all unauthenticated traffic.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>information-disclosure</category><category>api-security</category><category>cloud</category></item></channel></rss>