Finding · openhands
Security: Fix CVE-2026-44492 via axios upgrade to 1.16.0
What Changed
Updated axios dependency from 1.15.2 to 1.16.0 in frontend package to address CVE-2026-44492 security vulnerability.
Operator Implication
Operators must deploy this security patch to mitigate CVE-2026-44492 exposure in frontend HTTP client. Recommend applying at next maintenance window.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-03-openhands-cve-2026-44492-axios
Accepted signals
Profile citations
- OpenHands · claim · frontend-cve-cluster-and-acp-secrets
Source links
Primary links, including exact changelog lines when available.