OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries. | |
| Title | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T11:30:06.777Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85610
No data.
Status : Received
Published: 2026-09-04T12:17:24.463
Modified: 2026-09-04T12:17:24.463
Link: CVE-2026-85610
No data.
OpenCVE Enrichment
Updated: 2026-09-04T12:30:17Z
Weaknesses