Finding / openhands

Edited by Michael Ruescher

OpenHands' Authlib CVE fix remains on main

OpenHands still has no OSS tag after 1.8.0, and its Authlib update for CVE-2026-44681 remains main-only after the latest cloud tag. The vulnerability class is an OIDC open redirect / incorrect authorization flow in Authlib; operator impact is phishing leverage from a trusted authorization-server origin when vulnerable implicit or hybrid grants are exposed. Channel: main-unreleased. Operator consequence: OpenHands self-hosters cannot obtain this fix from a public OSS release tag in this window.

Receipt

Finding metadata

Run: 2026-07-02-weekly-digest-2026-07-01_2026-07-02-frontier-v0

Finding ID: 2026-07-02-openhands-authlib-cve-still-main-only

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact