Unknown · Openpanel Js-Runtime · CVE-2026-93985
**Name of the Vulnerable Software and Affected Versions**
OpenPanel js-runtime versions prior to commit bad75bdd
**Description**
A sandbox escape exists in the JavaScript webhook template validator. The validator fails to block computed member access to constructor chains, allowing users with project write access to bypass restrictions. By using computed property notation instead of direct dot notation, an attacker can access the `Function` constructor and execute arbitrary code within the worker process.
**Recommendations**
Update to a version beyond commit bad75bdd.
Restrict permissions for users who can create or edit webhook templates.