CVE-2026-46711 Details
Description
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.
A vulnerability exists in Soft Machine Fly Workspaces in versions through 0.2.247, where the workspace HTTP service on port 8080 exposes several endpoints without authentication or origin checks. This allows any host that can access the workspace's HTTP service to read arbitrary files from the workspace's root directory and download entire project trees as tar archives. The vulnerability arises because all workspaces share the same Fly private network, enabling unauthenticated access to files across different workspaces within the same Fly application or organization.
Workspace owners should be advised to bind the workspace API to a Unix socket or loopback only, or to require a per-workspace bearer token on every request that is only available to the workspace owner's session. Additionally, the hardcoded database JWT should be rotated immediately and moved out of the workspace service source code into a runtime secret that is not included in the workspace tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Soft-Machine-io/security/security/advisories/GHSA-h6g6-qr45-qmrr | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Soft-Machine-io/security/security/advisories/GHSA-h6g6-qr45-qmrr | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Soft Machine | <= 0.2.247 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion