CVE-2022-44760: Hcltech Hcl Leap

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

Affected products

  • Hcltech Hcl Leap: from 9.0, before 9.3.1 (fixed in 9.3.1)

Published 2025-04-24. Last modified 2026-06-17.