Finding / openhands
OpenHands' Authlib CVE fix remains on main
OpenHands still has no OSS tag after 1.8.0, and its Authlib update for
CVE-2026-44681 remains main-only after the latest cloud tag. The vulnerability
class is an OIDC open redirect / incorrect authorization flow in Authlib; operator
impact is phishing leverage from a trusted authorization-server origin when
vulnerable implicit or hybrid grants are exposed. Channel: main-unreleased.
Operator consequence: OpenHands self-hosters cannot obtain this fix from a public
OSS release tag in this window.
Receipt
Finding metadata
Run: 2026-07-02-weekly-digest-2026-07-01_2026-07-02-frontier-v0
Finding ID: 2026-07-02-openhands-authlib-cve-still-main-only
Source links
Primary links, including exact changelog lines when available.
- git commitOpenHands' Authlib CVE fix remains on maingithub.com/OpenHands/OpenHands/commit/e6fe5057fcc020069e05529c85107cba3e0c127fnvd recordOpenHands' Authlib CVE fix remains on mainnvd.nist.gov/vuln/detail/CVE-2026-44681ghsa recordOpenHands' Authlib CVE fix remains on maingithub.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2
Versioned source: run artifact