OpenPanel 在提交 bad75bdd 之前的 js-runtime 版本中,JavaScript Webhook 模板验证器存在一个沙箱逃逸漏洞,该验证器未能阻止通过计算属性访问构造函数链。拥有项目写权限的攻击者可以利用计算属性符号访问 构造函数,从而在 worker 进程中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ bad75bddc74d12d36cfb843f4531d3b830a8d994 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93984 | 5.3 MEDIUM | OpenPanel API Authentication Bypass via Unverified Client Secret |
| CVE-2026-93983 | 5.0 MEDIUM | OpenPanel SQL Injection via ClickHouse Property Key Filter |
| CVE-2026-93982 | 3.3 LOW | OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext |
No comments yet