Evidence record / openhands
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
Security: Fix CVE-2026-41238 via dompurify upgrade to 3.4.0
What Changed
Updated dompurify from 3.3.2 to 3.4.0 to address CVE-2026-41238 security vulnerability affecting HTML sanitization in frontend.
Operator Implication
Operators must deploy this security patch to mitigate CVE-2026-41238 exposure in HTML/DOM sanitization. Frontend users could be affected by insufficient sanitization if vulnerability remains unpatched.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-02-openhands-cve-2026-41238-dompurify
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact