← Scan another repo

github.com/OpenHands/OpenHands

@ 0ffcb659d1d4

Submitted 8/4/2026, 10:25:55 AM · Status: ok

Risk grade
F
100 / 100
Findings
313
0 critical4 high308 medium1 low0 info0 on CISA KEV0ATT&CK
Showing 313 of 313 findings

Findings

  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
    grype
  • React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
    This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths. > [!NOTE] > This only affects your application if you are using the unstable RSC APIs
    trivy

This report is public.