---
cve: "CVE-2026-63466"
severity: "MEDIUM"
cvss: 4.1
epss: "0.2%"
vendor: "Unleash"
kev: false
exploited: false
published: "2026-08-21 19:17:32"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-25T00:00:46+02:00"
---

# CVE-2026-63466

> 4.1 MEDIUM · 🧪 PoC

## Beschreibung

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. Because Mustache.escape is process-wide, the assignment disables escaping for subsequent Mustache.render calls in email-service.ts, webhook.ts, datadog.ts, and new-relic.ts. An editor-level user can place Slack or Microsoft Teams link syntax in an unrestricted username, trigger a feature event, and inject an attacker-labeled link into a trusted outbound notification channel, while other Mustache sinks remain unescaped until restart. This issue is fixed in version 8.0.3.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 002012cfdbedd2e9b7db9dc83b9f549f761db22e (Commit)
- ebb398aeeefaf3bb8b4020237d1b706462d1a00e (Commit)

## Referenzen

- <https://github.com/Unleash/unleash/security/advisories/GHSA-w4mq-xh27-6xpx>
- <https://github.com/Unleash/unleash/commit/002012cfdbedd2e9b7db9dc83b9f549f761db22e>
- <https://github.com/Unleash/unleash/releases/tag/v8.0.3>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-63466) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
