Sceawere

Vulnerability Detail

CVE-2026-108711UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plastic Labs Honcho Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
Plastic Labs
Product
honcho
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks only the workspace claim. Attackers can submit their parent workspace name to the POST /v3/workspaces endpoint to retrieve workspace metadata and configuration, including custom_instructions, reserved for workspace or admin keys.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:13.877Z",
  "pubdate": "2026-10-11T13:17:13.877Z",
  "executiveSummary": "Plastic Labs Honcho versions through 3.3.0 contain an incorrect authorization vulnerability in the workspace management logic.\nThe vulnerability, classified as an access control flaw, allows users holding peer- or session-scoped API keys to bypass intended authorization boundaries.\nBy manipulating requests to the POST /v3/workspaces endpoint, an attacker can access workspace metadata and configuration data that should be restricted to workspace-level or administrative keys.\nThe root cause lies in improper validation within the get_or_create_workspace function, which relies solely on workspace claim verification rather than enforcing granular authorization checks.\nThis vulnerability exposes sensitive organizational data, including custom_instructions, potentially leading to information disclosure and loss of confidentiality regarding internal workflows or configurations.\nExploitation requires a valid, albeit lower-privileged, API key. Successful exploitation allows unauthorized read access to target workspace resources, posing a significant risk to the integrity and confidentiality of multi-tenant environments.",
  "technicalDetails": "The vulnerability resides in the backend logic governing workspace identification and resource provisioning, specifically within the get_or_create_workspace function. In affected versions of Honcho, the application fails to adequately distinguish between authorization scopes when processing requests to the POST /v3/workspaces endpoint.\nThe root cause is a flaw in the authorization middleware or logic layer that handles workspace requests. When the get_or_create_workspace function is invoked, it performs a validation check based primarily on the workspace claim present in the provided API key. This implementation assumes that the presence of a valid claim is sufficient for authorization, failing to verify whether the requester possesses the elevated privileges (workspace-level or administrative-level) required to access specific metadata and configurations.\nAn attacker can exploit this by submitting a request to the POST /v3/workspaces endpoint while specifying the name of a target workspace they are not authorized to manage. Because the backend code performs an insufficient check, it erroneously interprets the request as a legitimate attempt to retrieve or configure the workspace metadata. The system then processes the request, returning sensitive details that should remain protected from lower-privileged entities.\nThe attack flow proceeds as follows: First, an attacker obtains a valid peer- or session-scoped API key. Second, the attacker constructs a POST request targeting the /v3/workspaces endpoint, injecting the target workspace identifier into the request payload. Third, the get_or_create_workspace function receives the request and validates the existence of the workspace claim. Due to the lack of secondary authorization checks, the function proceeds to retrieve the requested workspace's metadata. Finally, the server returns the response body containing sensitive configuration details, including custom_instructions and internal settings intended only for administrative or workspace-specific owners.\nThis vulnerability effectively bypasses the Principle of Least Privilege by elevating the capabilities of session-scoped keys. The scope of impact includes unauthorized access to environment-specific configurations and potentially proprietary instructions embedded within the workspace metadata. The affected components involve the API request handling lifecycle, specifically the authorization logic applied to the workspace retrieval process."
}
CVE-2026-108711: Plastic Labs Honcho Authorization Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere