
OpenHands released v1.16.0 today. Before looking at the feature list, check the version boundary. Its official advisory for CVE-2026-33718 lists OpenHands 1.4.0 and earlier as affected by command injection in the Git diff handler. The fix landed in 1.5.0.
Post summary
OpenHands CVE-2026-33718 is a command injection flaw in the Git diff handler affecting <1.5.0, fixed in 1.5.0; users should upgrade to the patched version.



