๐Ÿ” CVE Alert

CVE-2026-63466

MEDIUM 4.1

Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. Because Mustache.escape is process-wide, the assignment disables escaping for subsequent Mustache.render calls in email-service.ts, webhook.ts, datadog.ts, and new-relic.ts. An editor-level user can place Slack or Microsoft Teams link syntax in an unrestricted username, trigger a feature event, and inject an attacker-labeled link into a trusted outbound notification channel, while other Mustache sinks remain unescaped until restart. This issue is fixed in version 8.0.3.

CWE CWE-116
Vendor unleash
Product unleash
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for unleash unleash

Be the first to know when new medium vulnerabilities affecting unleash unleash are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Unleash / unleash
< 8.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Unleash/unleash/security/advisories/GHSA-w4mq-xh27-6xpx github.com: https://github.com/Unleash/unleash/commit/002012cfdbedd2e9b7db9dc83b9f549f761db22e github.com: https://github.com/Unleash/unleash/releases/tag/v8.0.3