← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 21, 2026 · 18:21via CVEFeed

CVE-2026-63466 - Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

Brief

CVE ID : CVE-2026-63466

Published : Aug. 21, 2026, 6:21 p. m.

  • 48 minutes ago

Description : Unleash is an open-source feature management platform. Prior to 8.

  • 3, FeatureEventFormatterMd. format in src/lib/addons/feature-event-formatter-md. ts assigns Mustache. escape to an identity function before rendering action and path templates. Because Mustache. escape is process-wide, the assignment disables escaping for subsequent Mustache. render calls in email-service. ts, webhook. ts, datadog.

ts, and new-relic. ts. An editor-level user can place Slack or Microsoft Teams link syntax in an unrestricted username, trigger a feature event, and inject an attacker-labeled link into a trusted outbound notification channel, while other Mustache sinks remain unescaped until restart. This issue is fixed in version 8.

  • 3.
Read more on CVEFeed