CVE-2026-47722

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation. Version 0.3.2 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 20:17

Updated : 2026-07-30 16:41


NVD link : CVE-2026-47722

Mitre link : CVE-2026-47722

CVE.ORG link : CVE-2026-47722


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')