Finding · openhands
Security: Fix CVE-2026-41238 via dompurify upgrade to 3.4.0
What Changed
Updated dompurify from 3.3.2 to 3.4.0 to address CVE-2026-41238 security vulnerability affecting HTML sanitization in frontend.
Operator Implication
Operators must deploy this security patch to mitigate CVE-2026-41238 exposure in HTML/DOM sanitization. Frontend users could be affected by insufficient sanitization if vulnerability remains unpatched.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-02-openhands-cve-2026-41238-dompurify
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact