Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-93985: OpenPanel allows code execution through webhook templates
CVE-2026-93985 · published 6 days ago
Summary
OpenPanel's JavaScript template feature does not properly stop attackers from reaching the system's underlying code engine. If someone can edit project settings, they could craft a special template that runs any code they want on the server. Restrict write access to projects and apply the latest software updates that fix the template validator.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openpanel-dev | openpanel | <= bad75bddc74d12d36cfb843f4531d3b830a8d994 |
Original advisory text
OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Severity
9.4
Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published19 Sep 2026
Updated25 Sep 2026
First seen19 Sep 2026
Track software like this
Free during beta