通过 commit bad75bddc74d12d36cfb843f4531d3b830a8d994 引入的 OpenPanel 跟踪 API 在授权收入事件(revenue events)和机器人过滤(bot filtering)之前,未能验证客户端密钥(client secret)的密码学哈希值。攻击者仅需持有公开的客户端 ID(client ID),即可提供任意伪造的密钥,从而注入虚假的收入指标并绕过机器人检测过滤器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ bad75bddc74d12d36cfb843f4531d3b830a8d994 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93985 | 9.9 CRITICAL | OpenPanel js-runtime JavaScript Template Sandbox Escape RCE |
| CVE-2026-93983 | 5.0 MEDIUM | OpenPanel SQL Injection via ClickHouse Property Key Filter |
| CVE-2026-93982 | 3.3 LOW | OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext |
No comments yet