Description
OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Published: 2026-09-19
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A sandbox escape flaw exists in the JavaScript webhook template validator within OpenPanel's js-runtime component. The validator improperly blocks computed member access, allowing an attacker who has project-write permissions to craft a template that uses computed property notation to reach the Function constructor. By invoking this constructor, the attacker can execute arbitrary JavaScript code inside the worker process, effectively achieving remote code execution. This aligns with CWE-94, which describes code injection via interpreted or dynamic code execution.

Affected Systems

The vulnerability affects all OpenPanel installations that include the js-runtime component up to and including version 2.3.0. Any release that has not incorporated the subsequent patch is susceptible; newer releases beyond 2.3.0 are considered not vulnerable based on the current information.

Risk and Exploitability

The CVSS score of 9.4 categorizes the flaw as critical, yet the EPSS score is below 1%, indicating a very low probability of public exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, so there is no known widespread exploitation data. However, because the exploit requires only project-write permissions—a privilege that many users may possess—the attack surface is significant. If successfully exploited, the attacker gains control over the worker process, which could lead to full compromise of the OpenPanel environment and any underlying host system.

Generated by OpenCVE AI on October 2, 2026 at 16:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenPanel to a release newer than js-runtime 2.3.0, which includes the patch for the sandbox escape flaw.
  • Revoke or restrict project-write permissions for webhook template creation until the vulnerability is patched, limiting the attack surface to trusted users only.
  • Manually review and remove any existing webhook templates that use computed property notation or access the Function constructor; for an interim safeguard, implement a runtime check or simple blacklist to block such patterns.
  • Monitor system logs for unexpected webhook activity and consider isolating or sandboxing the worker process to contain potential exploitation.

Generated by OpenCVE AI on October 2, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process. OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Title OpenPanel js-runtime JavaScript Template Sandbox Escape RCE OpenPanel js-runtime through 2.3.0 JavaScript Template Sandbox Escape RCE
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Title OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
First Time appeared Openpanel
Openpanel openpanel
Weaknesses CWE-94
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*
Vendors & Products Openpanel
Openpanel openpanel
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Openpanel Openpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:00:44.881Z

Reserved: 2026-09-19T10:55:49.093Z

Link: CVE-2026-93985

cve-icon Vulnrichment

Updated: 2026-09-21T15:33:33.126Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T12:16:41.873

Modified: 2026-10-02T15:17:13.063

Link: CVE-2026-93985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:00:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')