OpenPanel 是一个数据分析平台。在所有已知版本中(截至本漏洞发布时尚无修复版本),其数据导入功能使用普通的 请求调用方提供的 URL,而未调用项目中已有的 SSRF 防护工具( )。 具体而言,在 中, 函数会直接对 发起 请求,而该字段仅通过 进行校验,因此诸如 或 之类的地址均可被接受。同时,共享的 工厂函数也为其他看似合理的提供者提供了相同的字段。 因此,任何已认证的organization成员——包括默认的 'member' 角色(该角色没有对应的 记录,而本应进行的访问级别检查会因 返回布尔值 而
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ worker | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88890 | 8.5 HIGH | OpenPanel SQL Injection via unvalidated profile filter column identifier |
| CVE-2026-88891 | 8.3 HIGH | OpenPanel Read-Only Access Level Enforcement Bypass via Mutations |
| CVE-2026-88893 | 7.5 HIGH | OpenPanel Unauthenticated Share Lookup Information Disclosure |
No comments yet