unleash-server has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-639 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Worst active — by depth score
CVE-2026-63462High· 7.5Unleash is an open-source feature management platform41CVE-2026-77426High· 7.1Unleash: Missing await on permission check + cross-project IDOR in admin API39CVE-2026-63004Medium· 5.5Unleash is an open-source feature management platform30CVE-2026-76910Medium· 5.3Unleash: Clone-feature lets a user copy a feature from a project they cannot read29CVE-2026-77425Medium· 4.3Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log24
unleash-server vulnerabilities
CVEs affecting unleash-server, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-76910Medium· 5.3Unleash: Clone-feature lets a user copy a feature from a project they cannot read
Unleash: Clone-feature lets a user copy a feature from a project they cannot read
CVE-2026-76909Low· 2.1Unleash: CR-approval email renders user-controlled raw HTML
Unleash: CR-approval email renders user-controlled raw HTML
CVE-2026-77426High· 7.1Unleash: Missing await on permission check + cross-project IDOR in admin API
Unleash: Missing await on permission check + cross-project IDOR in admin API
CVE-2026-77425Medium· 4.3Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
CVE-2026-63462High· 7.5Unleash is an open-source feature management platform
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericE…
CVE-2026-63004Medium· 5.5Unleash is an open-source feature management platform
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Team…
CVE-2026-63466Medium· 4.1Unleash is an open-source feature management platform
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templa…