THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w4mq-xh27-6xpx (medium) — Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

[GHSA] GHSA-w4mq-xh27-6xpx (medium) — Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

highgithub_advisoriesPublished 2026-08-21

GHSA-w4mq-xh27-6xpx Severity: medium CVE: CVE-2026-63466

Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

## Vulnerability Details

**File**: `src/lib/addons/feature-event-formatter-md.ts` **Line**: 355 (in v8.0.1; `format()` method)

### Root Cause

`FeatureEventFormatterMd.format()` does:

```ts Mustache

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w4mq-xh27-6xpx