
If someone on your team can edit webhook templates, CVE-2026-93985 is a sandbox escape into the OpenPanel worker. The js-runtime validator blocks payload.constructor.constructor() but accepts the same chain with computed property access. That is RCE for project-write users, not a toy template bug. Upgrade past commit bad75bdd, and lock who can create webhook templates until you do. https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-6f7h-cvp6-w9w5




