Open-source Platform Vulnerability in Unleash Affecting Feature Management
CVE-2026-63466

4.1MEDIUM

Key Information:

Vendor

Unleash

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-63466?

Unleash, an open-source feature management platform, has a vulnerability in the FeatureEventFormatterMd.format function that allows an editor-level user to exploit template rendering. This occurs due to the improper handling of escaping in Mustache templates, leading to the potential injection of malicious links into trusted outbound notifications, such as Slack or Microsoft Teams. This issue could allow an attacker to manipulate notifications via an unrestricted username, undermining the integrity of message channels. The vulnerability is resolved in version 8.0.3, emphasizing the importance of upgrading to mitigate such risks.

Affected Version(s)

unleash < 8.0.3

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.