CVE-2026-93985

Source
https://cve.org/CVERecord?id=CVE-2026-93985
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93985.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93985
Aliases
  • GHSA-6f7h-cvp6-w9w5
Published
2026-09-19T11:53:37Z
Modified
2026-10-04T02:47:17Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
OpenPanel js-runtime through 2.3.0 JavaScript Template Sandbox Escape RCE
Details

OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-94"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93985.json"
}
References

Affected packages

Git / github.com/openpanel-dev/openpanel

Affected ranges

Type
GIT
Repo
https://github.com/openpanel-dev/openpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "2.3.0"
        },
        {
            "fixed":  "2.3.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93985.json"