
🚨Critical - Soft Machine Cross-Workspace AuthZ Bypass via Shared Bearer Secret (CVE-2026-55176) Soft Machine auth helpers accept the global CONTAINER_SHARED_SECRET as a bearer token without enforcing workspace membership checks. Since the secret is shared across containers and exposed inside each workspace env, a tenant can call other tenants’ workspace APIs for cross-workspace read/write and destructive restore actions. 👉Affected: Soft Machine (security package, all versions; no patch available)
