openhands-agent-server is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
65
Medium Risk
The download-trajectory endpoint zips the raw conversation directory into a downloadable archive without masking its contents. Serialized conversation state such as base_state.json and meta.json embeds the agent and condenser LLM API keys, either in plaintext when no secret key is configured or as recoverable Fernet ciphertext when one is. Anyone who obtains an exported trajectory archive therefore recovers usable credentials, including cipher-encrypted custom secrets stored in the secret registry. The fix redacts secret-bearing fields and Fernet-encrypted values at the export boundary before the archive is written.
You are affected if you are using a version that falls within the vulnerable range and you export or share a conversation trajectory produced by the download-trajectory endpoint.
openhands-agent-server is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.37.0.
Upgrade the openhands-agent-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant