GHSA-2m8f-94rg-j65xMediumCVSS 5.3

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify...

Published
September 19, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

🔗 References (4)