3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether unleash-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.1
CVE-2026-63466
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
MEDIUM 5.5
CVE-2026-63004
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
HIGH 7.5
CVE-2026-63462
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes