Unleash: CR-approval email renders user-controlled raw HTML
GHSA-7hvx-28gp-mf6j · CVE-2026-76909
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
The change-request approval HTML email template renders fields as raw HTML. User who can create a change request can inject HTML into approval notification emails. I was not able to confirm Enterprise platform is using vulnerable code nor that it doesn't sanitize input.
Details
src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache uses Mustache triple-stash syntax for fields that can originate from users:
{{{ changeRequestTitle }}}
{{{ requesterName }}}
{{{ requesterEmail }}}
{{{ changeRequestLink }}}
Triple-stash disables HTML escaping even when Mustache's global escape function is safe. The related renderer is sendRequestedCRApprovalEmail in src/lib/services/email-service.ts, which renders the template with Mustache.render.
PoC
- Use an Enterprise deployment with change requests and approval emails enabled.
- As a project member who can create change requests, set a display name or change-request title to HTML such as:
</a><a href="https://example.com">Approve change request</a>
- Create a change request that requires approval.
- Observe that the approval email contains attacker-controlled raw HTML instead of escaped text.
Impact
Change-request approvers can receive forged links, tracking pixels, or visually altered email content.
Ready to move
Start Securing
Free, no credit card | First findings in minutes