CVE-2026-55176: Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINERSHAREDSECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments are exposed when CONTAINER_SHARED_SECRET is identical across workspace containers and is available from the user-facing process environment within each workspace. The issue affects Soft Machine versions 0.2.247 and earlier.
What access does an attacker need to exploit this?
An attacker needs access to a paying customer's workspace shell, where they can reach the user-facing process environment and obtain the shared bearer secret. They can then present that secret to authenticate to another tenant's workspace API.
Does the per-workspace token validation prevent this attack?
No. The per-workspace workspaceTokenMatches validation applies to the per-workspace token path, but the shared-secret bearer-token path bypasses that check entirely.
Is a patch available?
At the time of publication, there are no publicly known patches.