CVE-2026-76909Low· 2.1▾ SunlitUnleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 11.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTitle, requesterName, and requesterEmail values without HTML escaping, and sendRequestedCRApprovalEmail passes those values to Mustache rendering. A project member who can create a change request when approval emails are enabled can inject HTML into an approver's notification, allowing forged links, tracking content, or visually altered email content. This issue is fixed in version 8.0.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
unleash-server < 8.0.3Patched in:
unleash-server 8.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76910Medium· 5.3Unleash is an open-source feature management platform
CVE-2026-77425Medium· 4.3Unleash is an open-source feature management platform
CVE-2026-77426High· 7.1Unleash is an open-source feature management platform
CVE-2026-63466Medium· 4.1Unleash is an open-source feature management platform
CVE-2026-63462High· 7.5Unleash is an open-source feature management platform
CVE-2026-63004Medium· 5.5Unleash is an open-source feature management platform