๐Ÿ” CVE Alert

CVE-2026-47722

UNKNOWN 0.0

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` โ€” no character or shape validation. Version 0.3.2 fixes the issue.

CWE CWE-94
Vendor juev
Product nebula-mesh
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for juev nebula-mesh

Be the first to know when new unknown vulnerabilities affecting juev nebula-mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

juev / nebula-mesh
< 0.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7hp6-g3pq-3pc3 github.com: https://github.com/forgekeep/nebula-mesh/issues/126 github.com: https://github.com/forgekeep/nebula-mesh/commit/c1506f7344ab375a145a7449b193af3f19bb41ef