Executive brief
OpenPanel is an open-source analytics platform that processes and visualizes user event data. An authenticated user with read access to analytics charts can inject malicious SQL commands through filter names to bypass project isolation boundaries and view metrics and event counts from other customers' projects on the same instance, exposing confidential business analytics data.
Technical details
OpenPanel's chart service fails to properly escape property key values when constructing ClickHouse SQL queries, allowing SQL injection via the non-wildcard branch of getSelectPropertyKey(). An authenticated attacker can inject boolean SQL terms (e.g., OR 1=1) through series[].filters[].name to override the project_id constraint, reaching the shared ClickHouse multi-tenant backend over the network. The vulnerability is read-only and requires prior authentication but enables cross-project data leakage.
Affected products
- OpenPanel OpenPanel through commit bad75bdd
Timeline
- 2026-09-19: disclosed