HTML Injection Vulnerability in Unleash Feature Management Platform
CVE-2026-76909
2.1LOW
What is CVE-2026-76909?
The Unleash Feature Management Platform, an open-source tool for managing feature toggles, was found to be vulnerable to HTML injection prior to version 8.0.3. The vulnerability arises from the improper rendering of user-controlled values, such as changeRequestTitle, requesterName, and requesterEmail in the approval email template. By exploiting this flaw, a malicious project member could inject arbitrary HTML into the email notifications sent to approvers, enabling forged links or manipulated content. This issue has been rectified in version 8.0.3, highlighting the importance of updating to protect against potential exploits.
Affected Version(s)
unleash < 8.0.3
