Impact
A sandbox escape flaw exists in the JavaScript webhook template validator within OpenPanel's js-runtime component. The validator improperly blocks computed member access, allowing an attacker who has project-write permissions to craft a template that uses computed property notation to reach the Function constructor. By invoking this constructor, the attacker can execute arbitrary JavaScript code inside the worker process, effectively achieving remote code execution. This aligns with CWE-94, which describes code injection via interpreted or dynamic code execution.
Affected Systems
The vulnerability affects all OpenPanel installations that include the js-runtime component up to and including version 2.3.0. Any release that has not incorporated the subsequent patch is susceptible; newer releases beyond 2.3.0 are considered not vulnerable based on the current information.
Risk and Exploitability
The CVSS score of 9.4 categorizes the flaw as critical, yet the EPSS score is below 1%, indicating a very low probability of public exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, so there is no known widespread exploitation data. However, because the exploit requires only project-write permissions—a privilege that many users may possess—the attack surface is significant. If successfully exploited, the attacker gains control over the worker process, which could lead to full compromise of the OpenPanel environment and any underlying host system.
OpenCVE Enrichment