VDB
Sign up
LOW

GHSA-7hvx-28gp-mf6j

Unleash: CR-approval email renders user-controlled raw HTML

Quick fix

GHSA-7hvx-28gp-mf6j — unleash-server: upgrade to the fixed version with the command below.

npm install unleash-server@8.0.3

Details

### Summary The change-request approval HTML email template renders fields as raw HTML. User who can create a change request can inject HTML into approval notification emails. I was not able to confirm Enterprise platform is using vulnerable code nor that it doesn't sanitize input.

### Details `src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache` uses Mustache triple-stash syntax for fields that can originate from users:

```mustache {{{ changeRequestTitle }}} {{{ requesterName }}} {{{ requesterEmail }}} {{{ changeRequestLink }}} ```

Triple-stash disables HTML escaping even when Mustache's global escape function is safe. The related renderer is `sendRequestedCRApprovalEmail` in `src/lib/services/email-service.ts`, which renders the template with `Mustache.render`.

### PoC 1. Use an Enterprise deployment with change requests and approval emails enabled. 2. As a project member who can create change requests, set a display name or change-request title to HTML such as:

```html </a><a href="https://example.com">Approve change request</a> ```

3. Create a change request that requires approval. 4. Observe that the approval email contains attacker-controlled raw HTML instead of escaped text.

### Impact Change-request approvers can receive forged links, tracking pixels, or visually altered email content.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/unleash-server
Introduced in: 0Fixed in: 8.0.3
Fixnpm install unleash-server@8.0.3

References