GHSA-6vg6-383g-xj2wHighCVSS 8.5

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.

🔗 References (4)