Security: Unleash/unleash
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headersGHSA-5vf6-jrqr-78fj published
Jul 1, 2026 by chriswkModerate -
A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit logGHSA-5ffh-6f9q-5hhr published
Jul 13, 2026 by chriswkModerate -
Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted usernameGHSA-w4mq-xh27-6xpx published
Jul 10, 2026 by chriswkModerate -
Unauthenticated single-request DoS via OpenAPI validation error formatterGHSA-r5pq-6chh-j3xp published
Jul 1, 2026 by chriswkHigh -
CR-approval email renders user-controlled raw HTMLGHSA-7hvx-28gp-mf6j published
Jul 10, 2026 by chriswkLow -
Clone-feature lets a user copy a feature from a project they cannot readGHSA-8xcj-9hfr-fh9j published
Jul 10, 2026 by chriswkModerate -
Missing await on permission check + cross-project IDOR in admin APIGHSA-72h8-wp98-7hch published
Jul 13, 2026 by chriswkHigh
Learn more about advisories related to Unleash/unleash in the GitHub Advisory Database