{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenpaneljs-runtime/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openpanel:js-runtime:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-93985"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["js-runtime (\u003c= bad75bdd)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","sandbox-escape","arbitrary-code-execution"],"_cs_type":"advisory","_cs_vendors":["OpenPanel"],"content_html":"\u003cp\u003eCVE-2026-93985 describes a critical sandbox escape vulnerability in the OpenPanel js-runtime, affecting all versions up to commit bad75bdd. The vulnerability resides within the JavaScript webhook template validator, which does not properly restrict computed member access to constructor chains. By leveraging computed property notation within a webhook template, an authenticated attacker with project write access can bypass sandbox restrictions to reach the Function constructor. This allows for the execution of arbitrary JavaScript code within the context of the underlying worker process. This vulnerability is highly impactful due to the direct escalation from project-level write access to system-level code execution within the worker environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authenticated access to an OpenPanel instance with 'project write' permissions.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the webhook template management interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious JavaScript payload utilizing computed property notation (e.g., [constructor]).\u003c/li\u003e\n\u003cli\u003eAttacker saves the payload into a webhook template.\u003c/li\u003e\n\u003cli\u003eThe OpenPanel js-runtime triggers the validator to process the template.\u003c/li\u003e\n\u003cli\u003eThe validator fails to block the access to the Function constructor chain.\u003c/li\u003e\n\u003cli\u003eThe runtime executes the attacker-controlled code within the worker process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker arbitrary code execution capabilities within the worker process of the OpenPanel js-runtime. This could lead to sensitive data exfiltration, lateral movement within the infrastructure, or service disruption. Given the high CVSS score of 9.9, the risk to organizations utilizing OpenPanel for webhook management is critical, as it bypasses intended security boundaries.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all existing webhook templates created or modified by non-administrative users.\u003c/li\u003e\n\u003cli\u003ePatch OpenPanel js-runtime to a version beyond commit bad75bdd immediately once a fix is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for the OpenPanel management interface to limit potential unauthorized project-level access.\u003c/li\u003e\n\u003cli\u003eReview worker process permissions to enforce the principle of least privilege, minimizing the potential impact of an arbitrary code execution event.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T14:12:01Z","date_published":"2026-09-19T14:12:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openpanel-js-runtime-sandbox-escape/","summary":"A sandbox escape vulnerability in the OpenPanel js-runtime allows authenticated users with project write access to achieve arbitrary code execution via the webhook template validator.","title":"Sandbox Escape in OpenPanel js-runtime via Webhook Template Validator","url":"https://feed.craftedsignal.io/briefs/2026-09-openpanel-js-runtime-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openpanel:js-Runtime:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}