Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-93985: OpenPanel allows code execution through webhook templates

CVE-2026-93985 · published 6 days ago
Summary

OpenPanel's JavaScript template feature does not properly stop attackers from reaching the system's underlying code engine. If someone can edit project settings, they could craft a special template that runs any code they want on the server. Restrict write access to projects and apply the latest software updates that fix the template validator.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
openpanel-dev openpanel <= bad75bddc74d12d36cfb843f4531d3b830a8d994
Original advisory text
OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Severity
9.4 Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published19 Sep 2026
Updated25 Sep 2026
First seen19 Sep 2026
Sources
CVE-2026-93985 · MITRE
Track software like this
Free during beta