VulnSea

unleash-server has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-639 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
Last 90 days
7 prev 0

Products

  • unleash-server 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

unleash-server vulnerabilities

CVEs affecting unleash-server, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-76910Medium· 5.3
today

Unleash: Clone-feature lets a user copy a feature from a project they cannot read

Unleash: Clone-feature lets a user copy a feature from a project they cannot read

Sunlitunleash-server · unleash-servervia GHSA
CVE-2026-76909Low· 2.1
today

Unleash: CR-approval email renders user-controlled raw HTML

Unleash: CR-approval email renders user-controlled raw HTML

Sunlitunleash-server · unleash-servervia GHSA
CVE-2026-77426High· 7.1
today

Unleash: Missing await on permission check + cross-project IDOR in admin API

Unleash: Missing await on permission check + cross-project IDOR in admin API

Twilightunleash-server · unleash-servervia GHSA
CVE-2026-77425Medium· 4.3
today

Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log

Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log

Sunlitunleash-server · unleash-servervia GHSA
CVE-2026-63462High· 7.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericE…

Twilightunleash-server · unleash-serverEPSS 0.48%via NVD
CVE-2026-63004Medium· 5.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Team…

Sunlitunleash-server · unleash-serverEPSS 0.34%via NVD
CVE-2026-63466Medium· 4.1
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templa…

Sunlitunleash-server · unleash-serverEPSS 0.18%via NVD
unleash-server vulnerabilities (CVEs) · VulnSea