What happened
Companion High-severity advisory to CVE-2026-55176: the in-workspace HTTP service has no auth or origin validation, so workspace filesystem content is readable by any network peer. It pairs with the cross-tenant token flaw to broaden lateral reach within the Fly network.
Why it matters
Workspaces in an agentic cloud IDE contain source code, config, and secrets; an unauthenticated file/archive read endpoint turns network adjacency into full workspace data exfiltration with no credentials.
Attack vector
The workspace HTTP service listening on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes /health, /file/<path>, and /archive/<dir> with no authentication or origin checking; any reachable peer can read arbitrary workspace files and download full directory archives.
Affected systems
Soft Machine workspace HTTP service, versions 0.2.247 and prior
Mitigation
Upgrade to a patched Soft Machine release per advisory GHSA-h6g6-qr45-qmrr; otherwise firewall port 8080 and restrict origin checks.