---
id: CVE-2026-93985
title: >-
  OpenPanel js-runtime through commit bad75bdd contains a sandbox escape
  vulnerability in the JavaScript webhook template validator that fails to block
  computed member access to constructor chains
summary: >-
  OpenPanel js-runtime through commit bad75bdd contains a sandbox escape
  vulnerability in the JavaScript webhook template validator that fails to block
  computed member access to constructor chains. Attackers with project write
  access can c…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: Openpanel-dev
product: openpanel
affected:
  - openpanel <= bad75bddc74d12d36cfb843f4531d3b830a8d994
published: '2026-09-19'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93985'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-6f7h-cvp6-w9w5
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-js-runtime-javascript-template-sandbox-escape-rce
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-6f7h-cvp6-w9w5
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00666
epssPercentile: 0.49651
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T15:32:34.101291Z'
ingestedAt: '2026-09-19T12:02:33.562Z'
---

## Overview

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
