CVE-2026-46711
Received Received - Intake

Soft Machine Workspace Arbitrary File Read via Unauthenticated HTTP Endpoints

Vulnerability report for CVE-2026-46711, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
soft_machine soft_machine to 0.2.247 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-46711 is a high-severity vulnerability in the Soft Machine workspace platform. It involves an unauthenticated HTTP service running on port 8080 that exposes endpoints like /file/<path> and /archive/<dir> without authentication or origin checks. This allows any host with network access to read arbitrary files or download entire project directories from the workspace root.

Detection Guidance

Check if the Soft Machine workspace HTTP service is listening on 0.0.0.0:8080 by running netstat -tulnp | grep 8080 or ss -tulnp | grep 8080. Verify if unauthenticated endpoints like /health, /file/<path>, or /archive/<dir> are accessible by sending HTTP requests to these paths using curl http://localhost:8080/health or curl http://localhost:8080/file/etc/passwd.

Inspect network traffic for connections to TCP port 8080 between Fly private network peers using tcpdump -i any port 8080 or Wireshark filters. Check for unauthorized file access attempts in logs by examining workspace logs for suspicious /file or /archive requests.

Impact Analysis

This vulnerability allows attackers to read sensitive files such as source code, configuration files (.env), SSH keys, and build artifacts. It can also enable downloading entire project trees as tar archives. Since the attack occurs over the Fly private network, any other workspace in the same Fly app or organization can be targeted, potentially leading to cross-tenant data exposure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA. Exposure of personal or health information due to arbitrary file reads may result in regulatory penalties, data breach notifications, and reputational damage.

Mitigation Strategies

Immediately restrict the workspace HTTP service to localhost by binding it to 127.0.0.1:8080 instead of 0.0.0.0:8080. Add per-workspace bearer token authentication to all exposed endpoints (/health, /file/<path>, /archive/<dir>).

Rotate any hardcoded JWT secrets found in workspace configurations, especially those used by Cursor MCP servers. Monitor network traffic for unauthorized access attempts and isolate affected workspaces until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46711. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart