openhands-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
59
Medium Risk
The remote conversation WebSocket client builds its connection URL by appending the session API key as a session_api_key query parameter. Full request URLs are routinely recorded by reverse proxies, load balancers, referrers, and access logs, so the credential is written into those logs in cleartext. Anyone able to read that log or telemetry data can recover the session API key and reuse it against the agent server. The fix removes the key from the URL and instead sends it in an initial WebSocket authentication message.
You are affected if you are using a version that falls within the vulnerable range and you use a remote conversation client configured with a session API key.
openhands-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.37.1.
Upgrade the openhands-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant