CVE-2026-108711
Received Received - Intake

Incorrect Authorization in Plastic Labs Honcho Allows Unauthorized Workspace Data Access

Vulnerability report for CVE-2026-108711, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Plastic Labs honcho 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Plastic Labs Honcho through version 3.3.0 has an authorization flaw where users with peer or session-scoped API keys can access workspace data meant for workspace or admin keys. The vulnerability occurs because the get_or_create_workspace function only checks the workspace claim, allowing attackers to submit a parent workspace name to the POST /v3/workspaces endpoint and retrieve sensitive metadata and configuration like custom_instructions.

Detection Guidance

To detect this vulnerability, inspect API requests to the POST /v3/workspaces endpoint. Check if peer- or session-scoped tokens can retrieve workspace metadata like custom_instructions. Use tools like curl to test with different token scopes and verify unauthorized access. Example: curl -H 'Authorization: Bearer <token>' -X POST -H 'Content-Type: application/json' -d '{"name":"<workspace_name>"}' https://api.honcho.dev/v3/workspaces

Monitor logs for unauthorized workspace data access attempts. Verify that workspace-scoped or admin tokens are the only ones permitted to read sensitive workspace configurations.

Impact Analysis

If you use Plastic Labs Honcho with API keys that are not workspace or admin-scoped, an attacker could exploit this flaw to read workspace data, including configurations and instructions. This may lead to unauthorized access to sensitive information, data leaks, or misuse of workspace settings.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by allowing unauthorized access to sensitive data. Exposure of workspace configurations or custom instructions may result in data breaches, leading to potential legal penalties, reputational damage, and failure to meet regulatory standards for data protection and access controls.

Mitigation Strategies

Update Plastic Labs Honcho to the latest version beyond 3.3.0 to address the authorization flaw. Restrict API key permissions to the minimum required scope and avoid using parent workspace names in API requests. Review and audit all active API keys for potential misuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108711. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart