๐Ÿ” CVE Alert

CVE-2026-108739

HIGH 7.5

OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1/workspaces

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.

CWE CWE-306
Vendor openagents-org
Product openagents
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for openagents-org openagents

Be the first to know when new high vulnerabilities affecting openagents-org openagents are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

openagents-org / OpenAgents
0 โ‰ค launcher-v1.0.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/openagents-workspace-list-browserfabric-key-disclosure github.com: https://github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.py#L135-L177 github.com: https://github.com/openagents-org/openagents/blob/0824907096d4039d86dfc96b81f9eebf31a77ae7/workspace/backend/app/routers/workspaces.py#L326-L349 github.com: https://github.com/openagents-org/openagents vulncheck.com: https://www.vulncheck.com/advisories/openagents-workspace-through-launcher-1.0.17-unauthenticated-credential-exposure-via-v1-workspaces

Credits

HaiND from the Post and Telecommunication Institute of Technology