Skip to content

OpenHands

vcloud-1.40.0 scope: cloud Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

agent artificial-intelligence chatgpt claude-ai cli developer-tools
+2 more
llm openai

Affected surfaces

deps

Summary

AI summary

Version 1.40.0 adds Git history settings, admin provisioning for enterprise, Azure DevOps resolver mentions, Jira DC improvements, and several bug fixes including three CVE patches.

Full changelog

1.40.0 (2026-06-26)

What's Changed

Features

  • feat: Add full Git history user setting by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/14950
  • feat(enterprise): add admin user-provisioning endpoint by @chuckbutkus in https://github.com/OpenHands/OpenHands/pull/14864
  • feat: Use interrupt endpoint for agent pause UI by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/14972
  • feat: add default_sandbox_spec_id to user settings by @tofarr in https://github.com/OpenHands/OpenHands/pull/14985
  • feat(azure-devops): add resolver mentions + org-level one-click webhook setup by @ak684 in https://github.com/OpenHands/OpenHands/pull/14991
  • feat(jira-dc): email-mode auto-link, targeted repo lookup, and picker mentions by @ak684 in https://github.com/OpenHands/OpenHands/pull/15001

Bug Fixes

  • fix: avoid decrypting org_member.llm_api_key when not set by @saurya in https://github.com/OpenHands/OpenHands/pull/14898
  • fix: Fix CVE-2026-54285: Update @opentelemetry/core to 2.8.0 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14980
  • fix: Fix GHSA-4xgf-cpjx-pc3j: Update pydantic-settings to 2.14.2 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14979
  • fix: Fix CVE-2026-48712: Update protobufjs to 7.6.4 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14981
  • fix: handle None git_full_clone from DB in SaasSettingsStore by @tofarr in https://github.com/OpenHands/OpenHands/pull/14988
  • fix(frontend): stop polling app-conversations with task IDs on new conversation by @hieptl in https://github.com/OpenHands/OpenHands/pull/14989
  • fix: return actionable error when Jira DC token endpoint is unreachable by @ak684 in https://github.com/OpenHands/OpenHands/pull/14990
  • fix(llm): restore managed member-key fallback in effective LLM key resolution by @ak684 in https://github.com/OpenHands/OpenHands/pull/14992
  • fix: Fix CVE-2026-48779: Update ws to 8.21.0 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/15007
  • fix: remove duplicate Close button on the org invite links modal by @ak684 in https://github.com/OpenHands/OpenHands/pull/14974

Documentation

  • docs: fix dead link to self-hosting guide in README by @tomsen-ai in https://github.com/OpenHands/OpenHands/pull/14975

Maintenance

  • chore(security): add Python dependency freshness guardrails by @nehaaprasad in https://github.com/OpenHands/OpenHands/pull/13754
  • chore(deps-dev): bump jupyterlab from 4.5.7 to 4.5.9 by @dependabot[bot] in https://github.com/OpenHands/OpenHands/pull/15009

New Contributors

  • @tomsen-ai made their first contribution in https://github.com/OpenHands/OpenHands/pull/14975

Full Changelog: https://github.com/OpenHands/OpenHands/compare/cloud-1.39.0...cloud-1.40.0


This PR was generated with Release Please. See documentation.

Security Fixes

  • CVE-2026-54285 — Update @opentelemetry/core to 2.8.0
  • GHSA-4xgf-cpjx-pc3j — Update pydantic-settings to 2.14.2
  • CVE-2026-48712 — Update protobufjs to 7.6.4
  • CVE-2026-48779 — Update ws to 8.21.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenHands

Get notified when new releases ship.

Sign up free

About OpenHands

OpenHands: AI-Driven Development

All releases →

Related context

Earlier breaking changes

  • v1.8.0 Removes App tab from conversation UI.

Beta — feedback welcome: [email protected]