VYPR

unleash

by Unleash

CVEs (3)

  • CVE-2026-63462HigAug 21, 2026
    risk 0.42cvss 7.5epss

    Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessage and…

  • CVE-2026-63004MedAug 21, 2026
    risk 0.29cvss 5.5epss

    Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to…

  • CVE-2026-63466MedAug 21, 2026
    risk 0.20cvss 4.1epss

    Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. Because Mustache.escape is…