External risk intelligence

OpenPanel js-runtime Sandbox Escape Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-93985

The vulnerability exists in a webhook template validator within a JavaScript runtime. While webhooks are common in internet-facing applications, the requirement for an attacker to have project write access means this is not a pre-authentication endpoint reachable by anonymous external users, making public exploitation in common deployments possible but not a primary design feature.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in OpenPanel's JavaScript runtime that could allow unauthorized code execution. The issue stems from a flaw in how webhook templates are validated, potentially enabling attackers with project write access to compromise the worker process.

  • Code execution flaw in template validation.
  • Allows code execution with project write access.
  • Confirm relevance and exposure to affected systems.

Attack Path

How an attacker could exploit the issue

An attacker with project write access can exploit this vulnerability by creating specially crafted webhook templates. These templates leverage computed property access within the JavaScript runtime's validation logic, specifically targeting the webhook template validator. By manipulating this validator, an attacker can bypass its intended security checks and execute arbitrary code within the worker process.

  • Requires project write access.
  • Triggers via JavaScript webhook templates.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker with project write access could execute arbitrary code within the worker process by exploiting a sandbox escape vulnerability in the JavaScript webhook template validator. This could affect the behavior of services when specific webhook templates are processed.

  • Worker process code execution.
  • Project write access required.
  • Service behavior compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OpenPanel js-runtime's JavaScript webhook template validator is affected by a sandbox escape vulnerability. Attackers with project write access can exploit this by creating webhook templates that allow arbitrary code execution in the worker process. Ownership of this issue likely falls to the team managing the OpenPanel deployment, potentially involving application, platform, and security teams. The first practical step is to identify all instances of OpenPanel, determine their exposure and criticality, and then plan remediation based on these findings.

  • Application or Platform team owns the fix.
  • Verify webhook template usage and exposure.
  • Plan maintenance for code execution remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenPanel js-runtime and how is it used?

OpenPanel js-runtime is a component within the OpenPanel software suite designed to execute JavaScript code. It is primarily used to handle automation tasks, such as processing webhook templates that facilitate communication between applications and external services by executing logic within a dedicated worker process.

How does this sandbox escape work in CVE-2026-93985?

This vulnerability is a form of Improper Control of Generation of Code, or CWE-94. The validator intended to restrict webhook templates fails to block computed member access. This flaw allows an attacker to navigate the JavaScript constructor chain, ultimately reaching the Function constructor to execute unauthorized commands outside of the intended sandbox.

Does anonymous access trigger CVE-2026-93985?

No. A successful trigger requires the attacker to already possess project write access within the platform. This means that a user without legitimate administrative or authoring permissions to create and save webhook templates cannot initiate the exploit, as the malicious template must be submitted to the validator for processing.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that while the vulnerability is in an internet-facing service, it is not an anonymous entry point. Risk depends on whether you allow untrusted users to manage project webhook templates. If your deployment uses these webhooks, the potential for an internal user to escalate privileges or compromise the worker process is a serious consideration.

How do I start addressing this vulnerability?

Begin by auditing your environment to locate all instances of OpenPanel js-runtime currently in use. Once identified, review the permissions for project webhook creation to ensure only trusted users have access. Collaborate with your application and platform teams to prioritize these systems for maintenance and potential security updates as they become available.

References