Evidence record / openhands

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-07-01-openhands-cloud-1-40-0-tagged-2026-06-26-shipping-a-4-item-cve-ghs

cloud-1.40.0 tagged (2026-06-26) shipping a 4-item CVE/GHSA dependency-security batch plus enterprise/agent-control features (channel: tagged-release, 2026-06-26). Operator consequence: Cloud/enterprise operators on the OpenHands cloud line should upgrade: it closes CVE-2026-54285 (@opentelemetry/core 2.8.0, commit 648dba8), CVE-2026-48712 (protobufjs 7.6.4), CVE-2026-48779 (ws 8.21.0), and GHSA-4xgf-cpjx-pc3j (pydantic-settings 2.14.2). Also adds an enterprise admin user-provisioning endpoint, an agent pause/interrupt endpoint, and a default sandbox-spec ID user setting — re-audit provisioning and sandbox defaults. NOTE: none of this reaches the self-hosted OSS 1.8.0 line. Full receipted detail lives in harvest/watchlist.md.

Receipt

Finding metadata

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Finding ID: 2026-07-01-openhands-cloud-1-40-0-tagged-2026-06-26-shipping-a-4-item-cve-ghs

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact