Finding / openhands

2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xss

Four security fixes shipped as plain PRs: Electron link-origin bypass, runtime-config XSS, DOMPurify, and hidden confirmation prompts. Four security fixes shipped as plain PRs: Electron link-origin bypass, runtime-config XSS, DOMPurify, and hidden confirmation prompts

Channel: tagged-release. Half: defect. Date: 2026-09-09 (v1.17.0), 2026-09-16 (v1.19.0).

Operator consequence: Upgrade desktop installs to v1.17.0 or later. Self-hosters who serve Canvas through scripts/static-server.mjs should upgrade to v1.19.0 or later. If a proxy or shared browser may have cached a session key from an earlier page, rotate it. On versions before v1.17.0, do not assume “no prompt visible” means the agent is not waiting.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-openhands-four-security-fixes-shipped-as-plain-prs-electron-link-origin-bypass-runtime-config-xss

Profile citations

  • OpenHands / claim / security-fixes-without-advisories

Source links

Primary links, including exact changelog lines when available.