PT-2026-95822 · Unknown · Openpanel Js-Runtime

·

CVE-2026-93985

·

Published

2026-09-19

·

Updated

2026-09-21

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenPanel js-runtime versions prior to commit bad75bdd
Description A sandbox escape exists in the JavaScript webhook template validator. The validator fails to block computed member access to constructor chains, allowing users with project write access to bypass restrictions. By using computed property notation instead of direct dot notation, an attacker can access the Function constructor and execute arbitrary code within the worker process.
Recommendations Update to a version beyond commit bad75bdd. Restrict permissions for users who can create or edit webhook templates.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93985

Affected Products

Openpanel Js-Runtime