CVE-2026-63466 - Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Brief
CVE ID : CVE-2026-63466
Published : Aug. 21, 2026, 6:21 p. m.
- 48 minutes ago
Description : Unleash is an open-source feature management platform. Prior to 8.
- 3, FeatureEventFormatterMd. format in src/lib/addons/feature-event-formatter-md. ts assigns Mustache. escape to an identity function before rendering action and path templates. Because Mustache. escape is process-wide, the assignment disables escaping for subsequent Mustache. render calls in email-service. ts, webhook. ts, datadog.
ts, and new-relic. ts. An editor-level user can place Slack or Microsoft Teams link syntax in an unrestricted username, trigger a feature event, and inject an attacker-labeled link into a trusted outbound notification channel, while other Mustache sinks remain unescaped until restart. This issue is fixed in version 8.
- 3.
