CVE-2026-93983
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Summary
OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Openpanel-dev | openpanel | 0 <= bad75bddc74d12d36cfb843f4531d3b830a8d994 | affected |
Weaknesses
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-cc5p-97vc-8fwv
- https://www.vulncheck.com/advisories/openpanel-sql-injection-via-clickhouse-property-key-filter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.