What is CVE-2026-47722?
CVE-2026-47722 affects the 'nebula-mesh' self-hosted control plane for Slack Nebula VPN. Prior to version 0.3.2, the `ListenHost` and `TunDevice` fields are interpolated raw into a `text/template`, allowing malicious injection into the generated `config.yml`. Upgrading to version 0.3.2 or later mitigates this issue.
Azərbaycanca: CVE-2026-47722 'nebula-mesh' self-hosted kontrol panelində aşkar edilib. Operator tərəfindən verilən `ListenHost` və `TunDevice` sahələri `text/template` şablonunda təmizlənmədən istifadə edildiyi üçün `config.yml` faylına malicious inject etmək mümkündür. Bu zəiflikdən qorunmaq üçün 0.3.2 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which fields in nebula-mesh are exploited in CVE-2026-47722?
The vulnerability arises from the operator-supplied `ListenHost` and `TunDevice` fields being used raw in a `text/template` without sanitization.
How can CVE-2026-47722 be mitigated?
Upgrading nebula-mesh to version 0.3.2 or later mitigates this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.