Skip to content

[Bug bounty] monk.cluster.create logs workspaceRoot='C:\Windows\System32' against an active workspace session — workspace-context binding leaks across dashboard tabs (gauntlet step 4) #482

Description

@NyxSpecter4

Summary

Action id da8d9f48-818b-4ead-beba-b8606e2937f2 in the action store has workspaceId=ws_5ce1ff01e80213a86c54b1cb but workspaceRoot=C:\Windows\System32 — the dashboard bind path instead of the active workspace.

Stage

deploy

Repro steps

  1. Sign in as github|236979482 in Cursor
  2. Open the Monk dashboard in the foreground
  3. Issue monk.cluster.create from a different tab
  4. Read ~/.monk/agent/store/global/actions/items.json — workspaceId correctly points at the live workspace, but workspaceRoot is the dashboard's window-default

Expected

Either workspaceRoot is the bind point of workspaceId, OR the action is rejected before approval.

Actual

  • Action da8d9f48 logged workspaceRoot='C:\Windows\System32' against the active bountywarz workspace, then 15-minute approval window expired with no path validation.

Setup

Windows 11, Cursor with Monk coding-agent plugin v0.1.58, account github|236979482.

Evidence

Attached: monkd-action-store-cluster-create-2026-08-31T01-16-04.json

Bounty eligibility

  • Signed up at monk.io with GitHub (github|236979482)
  • Used the product (installed plugin and ran it)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions