Evidence record / openhands
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
OpenHands’ Authlib CVE fix remains on main
OpenHands still has no OSS tag after 1.8.0, and its Authlib update for
CVE-2026-44681 remains main-only after the latest cloud tag. The vulnerability
class is an OIDC open redirect / incorrect authorization flow in Authlib; operator
impact is phishing leverage from a trusted authorization-server origin when
vulnerable implicit or hybrid grants are exposed. Channel: main-unreleased.
Operator consequence: OpenHands self-hosters cannot obtain this fix from a public
OSS release tag in this window.
Receipt
Finding metadata
Run: 2026-07-02-weekly-digest-2026-07-01_2026-07-02-frontier-v0
Finding ID: 2026-07-02-openhands-authlib-cve-still-main-only
Source links
Primary links, including exact changelog lines when available.
- git commitOpenHands' Authlib CVE fix remains on maingithub.com/OpenHands/OpenHands/commit/e6fe5057fcc020069e05529c85107cba3e0c127fnvd recordOpenHands' Authlib CVE fix remains on mainnvd.nist.gov/vuln/detail/CVE-2026-44681ghsa recordOpenHands' Authlib CVE fix remains on maingithub.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2
Versioned source: run artifact