CVE-2026-85610: OpenPanel before 2.3.0 Remote Code Execution via chart formulas
OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated project member with read access can exploit it. The attacker does not need write-level project permissions or user interaction.
What level of access can successful exploitation provide?
Successful exploitation can run operating system commands with the privileges of the OpenPanel API process. It can also bypass organization authorization boundaries.
Which deployments are affected?
OpenPanel versions before 2.3.0 are affected. The issue is reachable through chart formula expressions.