๐Ÿ” CVE Alert

CVE-2026-108711

MEDIUM 4.3

Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.

CWE CWE-863
Vendor plastic labs
Product honcho
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for plastic labs honcho

Be the first to know when new medium vulnerabilities affecting plastic labs honcho are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Plastic Labs / honcho
0 โ‰ค 3.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/honcho-scoped-jwt-workspace-config-disclosure github.com: https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/routers/workspaces.py#L41-L72 github.com: https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/security.py#L218-L225 github.com: https://github.com/plastic-labs/honcho/blob/608aec8a928da13c540262ed980c569448fb53ab/src/crud/workspace.py#L112-L119 github.com: https://github.com/plastic-labs/honcho vulncheck.com: https://www.vulncheck.com/advisories/plastic-labs-honcho-through-3.3.0-incorrect-authorization-via-post-v3-workspaces

Credits

HaiND from the Post and Telecommunication Institute of Technology