Open-source Platform Vulnerability in Unleash Affecting Feature Management
CVE-2026-63466
4.1MEDIUM
What is CVE-2026-63466?
Unleash, an open-source feature management platform, has a vulnerability in the FeatureEventFormatterMd.format function that allows an editor-level user to exploit template rendering. This occurs due to the improper handling of escaping in Mustache templates, leading to the potential injection of malicious links into trusted outbound notifications, such as Slack or Microsoft Teams. This issue could allow an attacker to manipulate notifications via an unrestricted username, undermining the integrity of message channels. The vulnerability is resolved in version 8.0.3, emphasizing the importance of upgrading to mitigate such risks.
Affected Version(s)
unleash < 8.0.3
