Finding / openhands
2026-07-01-openhands-cloud-1-40-0-tagged-2026-06-26-shipping-a-4-item-cve-ghs
cloud-1.40.0 tagged (2026-06-26) shipping a 4-item CVE/GHSA dependency-security batch plus enterprise/agent-control features (channel: tagged-release, 2026-06-26). Operator consequence: Cloud/enterprise operators on the OpenHands cloud line should upgrade: it closes CVE-2026-54285 (@opentelemetry/core 2.8.0, commit 648dba8), CVE-2026-48712 (protobufjs 7.6.4), CVE-2026-48779 (ws 8.21.0), and GHSA-4xgf-cpjx-pc3j (pydantic-settings 2.14.2). Also adds an enterprise admin user-provisioning endpoint, an agent pause/interrupt endpoint, and a default sandbox-spec ID user setting — re-audit provisioning and sandbox defaults. NOTE: none of this reaches the self-hosted OSS 1.8.0 line. Full receipted detail lives in harvest/watchlist.md.
Receipt
Finding metadata
Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0
Finding ID: 2026-07-01-openhands-cloud-1-40-0-tagged-2026-06-26-shipping-a-4-item-cve-ghs
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact