Finding / openhands
2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xss
Four security fixes shipped as plain PRs: Electron link-origin bypass, runtime-config XSS, DOMPurify, and hidden confirmation prompts. Four security fixes shipped as plain PRs: Electron link-origin bypass, runtime-config XSS, DOMPurify, and hidden confirmation prompts
Channel: tagged-release. Half: defect. Date: 2026-09-09 (v1.17.0), 2026-09-16 (v1.19.0).
Operator consequence: Upgrade desktop installs to v1.17.0 or later. Self-hosters who serve Canvas through scripts/static-server.mjs should upgrade to v1.19.0 or later. If a proxy or shared browser may have cached a session key from an earlier page, rotate it. On versions before v1.17.0, do not assume “no prompt visible” means the agent is not waiting.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xss
Profile citations
- OpenHands / claim / security-fixes-without-advisories
Source links
Primary links, including exact changelog lines when available.
- merged pr2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xssgithub.com/OpenHands/OpenHands/pull/16961merged pr2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xssgithub.com/OpenHands/OpenHands/pull/17175merged pr2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xssgithub.com/OpenHands/OpenHands/pull/17060merged pr2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xssgithub.com/OpenHands/OpenHands/pull/17134