PT-2026-97038 · Unleash · Unleash
CVE-2026-76909
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Unleash versions prior to 8.0.3
Description
The change-request approval email template at
src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders user-controlled values without HTML escaping. The sendRequestedCRApprovalEmail function passes these values to Mustache rendering using triple-stash syntax, which disables HTML escaping. A project member capable of creating change requests can inject HTML into notifications sent to approvers. This allows for the inclusion of forged links, tracking content, or visually altered email content via the changeRequestTitle, requesterName, and requesterEmail variables.Recommendations
Update to version 8.0.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unleash