---
id: CVE-2026-85613
title: >-
  OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the
  unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote
  attackers to execute scripts by supplying an SVG file URL
summary: >-
  OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the
  unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote
  attackers to execute scripts by supplying an SVG file URL. Attackers can host
  malicio…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'
cwe:
  - CWE-79
vendor: Openpanel-dev
product: openpanel
affected:
  - openpanel < 2.3.0
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85613'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-r7hx-q6f4-vj6h
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-unauthenticated-xss-via-svg-favicon-proxy
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-r7hx-q6f4-vj6h
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00229
epssPercentile: 0.13948
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T16:30:09.911945Z'
ingestedAt: '2026-09-08T19:08:49.674Z'
---

## Overview

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
