Impact
OpenPanel versions prior to 2.3.0 contain a flaw where chart formula expressions are not validated correctly. An attacker who is an authenticated project member with read access can recover a native JavaScript Function constructor through mathjs matrix objects. With this constructor the attacker can load Node.js built‑in modules and execute arbitrary operating system commands using the privileges of the API process. This leads to full remote code execution on the server and effectively bypasses organization‑wide authorization boundaries. The weakness is classified as CWE‑94: Improper Control of Execute of Arbitrary Code via Dynamic Language Features.
Affected Systems
The vulnerability affects all installations of OpenPanel produced by Openpanel‑dev:openpanel for versions older than 2.3.0. Users running OpenPanel 2.2.x or earlier are susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates High severity. There is no EPSS data available, and the vulnerability has not been listed in CISA’s KEV catalog. Attackers need only authenticated read permission to a project; from that position they can exploit the flaw and run commands as the API service user. This grants full control of the underlying operating system. The combination of high severity and easy authentication requirements makes this a high‑risk vulnerability that should be mitigated promptly.
OpenCVE Enrichment