security vulnerabilities
CVEs whose affected-version data names the security package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55176Critical· 9.0Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global C…
▾ MidnightSoft-Machine-io · securityvia NVD
CVE-2026-46711High· 8.3PoCSoft Machine is a Virtual Machine–based agentic development environment / Cloud OS
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/…
▾ MidnightSoft-Machine-io · securityvia NVD