OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-108739 (CVSS 8.7)

NVD · officialPublished Oct 11, 2026Risk 37/100

OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.

CVSS
8.7
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source