CRITICAL
9.9 CVE-2026-93985 Published 19 Sept 2026
OpenPanel js-runtime Sandbox Escape Vulnerability
Worried this affects your website?
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator.
The validator fails to block computed member access to constructor chains, allowing attackers to reach the Function constructor.
- Affected versions: OpenPanel js-runtime through commit bad75bdd.
- Precondition: attacker has project write access.
- Impact: arbitrary code execution in the worker process.
Reference: CVE-2026-93985 on NVD
← Back to Security News