天下漏洞,尽知其名
HIGH

CVE-2026-46711 Soft Machine 工作区 HTTP 服务未授权文件读取漏洞

影响攻击者可未授权读取工作区任意文件并下载整个项目目录

AI 研判

Soft Machine 是基于虚拟机的智能体开发环境/云操作系统。其每个 sm-ws-* Fly Machine 内监听 0.0.0.0:8080 的工作区 HTTP 服务在 0.2.247 及更早版本中缺少认证与来源校验。任何能访问该端口的机器均可读取工作区 /workspace 下的任意文件,并以 tar 归档形式下载整个项目树。

影响范围

Soft Machine

漏洞详情

漏洞类型为缺失认证/访问控制(未授权文件读取)。成因是 /health、/file/<path>、/archive/<dir> 等端点未做任何身份验证或 Origin 检查。由于同一 Fly 应用/组织内的所有工作区共享私有 6PN 网络,并通过未认证的 _instances.internal TXT 记录解析对端地址,任意其他 sm-ws-* 机器都可作为未授权攻击者直接访问这些端点。

利用条件与风险

利用前提是攻击者能访问目标工作区 TCP/8080 端口,同一 Fly 应用/组织内的其他工作区天然满足该条件。实战中可导致源码、配置、密钥等敏感文件泄露,风险较高。

修复建议

截至发布时暂无公开补丁。建议限制 8080 端口暴露范围、在网络层隔离工作区间通信,或在服务前增加认证与来源校验;具体官方修复方案请关注厂商公告。

原始情报

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/, /archive/) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace’s /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.