unleash-server
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting unleash-serverpage 1 of 1
- CVE-2026-63004MEDIUMCVSS 5.5EG 5.5fixed in 7.5.2, 7.6.5 or 8.0.2, by version range2026-08-21
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams,…
- CVE-2026-63462HIGHCVSS 7.5EG 7.5fixed in 7.5.2, 7.6.5 or 8.0.2, by version range2026-08-21
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErr…
- CVE-2026-63466MEDIUMCVSS 4.1EG 4.1fixed in 8.0.32026-08-21
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path template…
- CVE-2026-76909LOWCVSS 2.1EG 2.1fixed in 8.0.32026-09-22
Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTitle…
- CVE-2026-76910MEDIUMCVSS 5.3EG 5.3fixed in 8.0.32026-09-22
Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the sou…
- CVE-2026-77425MEDIUMCVSS 4.3EG 4.3fixed in 8.0.32026-09-22
Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpda…
- CVE-2026-77426HIGHCVSS 7.1EG 7.1fixed in 8.0.32026-09-22
Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting it…
Check whether unleash-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for unleash-server CVEs against the assets you own.
Book a Demo →