CRITICAL 9.9 CVE-2026-93985 Published 19 Sept 2026

OpenPanel js-runtime Sandbox Escape Vulnerability

Worried this affects your website?

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator.

The validator fails to block computed member access to constructor chains, allowing attackers to reach the Function constructor.

  • Affected versions: OpenPanel js-runtime through commit bad75bdd.
  • Precondition: attacker has project write access.
  • Impact: arbitrary code execution in the worker process.

Reference: CVE-2026-93985 on NVD

← Back to Security News