← voltar
CVE-2026-46711highCWE-306

Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network

18Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.3
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L