Vulnerability Description
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-6f7h-cvp6-w9
- https://www.vulncheck.com/advisories/openpanel-js-runtime-javascript-template-sa
FAQ
What is CVE-2026-93985?
CVE-2026-93985 is a vulnerability with a CVSS score of 9.9 (CRITICAL). OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Atta...
How severe is CVE-2026-93985?
CVE-2026-93985 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-93985?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.