VulnSea

openpanel vulnerabilities

CVEs whose affected-version data names the openpanel package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-93983Medium· 5.0
2d ago

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics…

SunlitOpenpanel-dev · openpanelEPSS 0.20%via NVD
CVE-2026-93982Low· 3.3PoC
2d ago

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems c…

TwilightOpenpanel-dev · openpanelEPSS 0.11%via NVD
CVE-2026-93985Critical· 9.9PoC
2d ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

AbyssalOpenpanel-dev · openpanelEPSS 0.48%via NVD
CVE-2026-93984Medium· 5.3
2d ago

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitr…

SunlitOpenpanel-dev · openpanelEPSS 0.20%via NVD
CVE-2026-88890High· 8.5
1w ago

OpenPanel SQL Injection via unvalidated profile filter column identifier

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated…

TwilightOpenpanel-dev · openpanelEPSS 0.29%via CVEORG
CVE-2026-88893High· 7.5
1w ago

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report …

TwilightOpenpanel-dev · openpanelEPSS 0.31%via NVD
CVE-2026-88891High· 8.3PoC
1w ago

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboard…

MidnightOpenpanel-dev · openpanelEPSS 0.25%via NVD
CVE-2026-88892Medium· 5.0PoC
1w ago

OpenPanel is an analytics platform

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/…

TwilightOpenpanel-dev · openpanelEPSS 0.26%via NVD
CVE-2026-85615Medium· 6.4
2w ago

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supp…

SunlitOpenpanel-dev · openpanelEPSS 0.14%via NVD
CVE-2026-85612High· 7.5PoC
2w ago

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the…

MidnightOpenpanel-dev · openpanelEPSS 0.24%via NVD
CVE-2026-85610High· 8.8
2w ago

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix…

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix…

TwilightOpenpanel-dev · openpanelEPSS 0.39%via NVD
CVE-2026-85613High· 8.2PoC
2w ago

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicio…

MidnightOpenpanel-dev · openpanelEPSS 0.23%via NVD
openpanel vulnerabilities (CVEs) · VulnSea