CVE-2026-93985

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-09-20)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-09-19: 2Mentions · 2026-09-20: 309-1909-20
Referenced assets5 URLs
Full discourse5 posts
  • Anthony Bahn@HoustonIntrove1

    If someone on your team can edit webhook templates, CVE-2026-93985 is a sandbox escape into the OpenPanel worker. The js-runtime validator blocks payload.constructor.constructor() but accepts the same chain with computed property access. That is RCE for project-write users, not a toy template bug. Upgrade past commit bad75bdd, and lock who can create webhook templates until you do. https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-6f7h-cvp6-w9w5

    0000029
    23 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate

    🚨 OpenPanel js-runtime #CVE-2026-93985: Analyzing and Mitigating the CVSS 99 Sandbox Escape RCE + Video -Prediction: 📈 1 Positive | 📉 1 Negative https://undercodetesting.com/openpanel-js-runtime-cve-2026-93985-analyzing-and-mitigating-the-cvss-99-sandbox-escape-rce-video/ Educational Purposes!

    0000038
    739 followersView on X
  • ThreatAft@ThreatAft

    🚨 OPENPANEL JS-RUNTIME — CVSS 9.9 CVE-2026-93985: Sandbox escape payload.constructor.constructor() → BLOCKED payload['constructor']['constructor']() → ACCEPTED → https://threataft.com/articles/openpanel-js-runtime-cve-2026-93985-sandbox-escape #OpenPanel #CVE #RCE #SandboxEscape #PatchNow #CyberSecurity #ThreatIntel

    0000032
    43 followersView on X
  • CVE@CVEnew

    CVE-2026-93985 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member … https://www.cve.org/CVERecord?id=CVE-2026-93985

    000001.5K
    58.1K followersView on X
  • Severity Daily@severitydaily

    OpenPanel's 9.9 webhook RCE has no patched version — the project has never cut a release, so the CVE VulnCheck (@VulnCheckAI) published today names a git commit hash instead. No exploitation reported. https://severitydaily.com/openpanel-cve-2026-93985-webhook-sandbox-escape-no-patched-version-commit-hash/

    0000033
    24 followersView on X

Explore more