PT-2026-97038 · Unleash · Unleash

CVE-2026-76909

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Unleash versions prior to 8.0.3
Description The change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders user-controlled values without HTML escaping. The sendRequestedCRApprovalEmail function passes these values to Mustache rendering using triple-stash syntax, which disables HTML escaping. A project member capable of creating change requests can inject HTML into notifications sent to approvers. This allows for the inclusion of forged links, tracking content, or visually altered email content via the changeRequestTitle, requesterName, and requesterEmail variables.
Recommendations Update to version 8.0.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76909
GHSA-7HVX-28GP-MF6J

Affected Products

Unleash