What is CVE-2026-47725?
CVE-2026-47725 is a vulnerability in the self-hosted control plane nebula-mesh for Slack Nebula. In versions prior to 0.3.3, POST/PUT/PATCH/DELETE requests to /ui/* are processed immediately upon session cookie validation, potentially allowing CSRF attacks to bypass the SameSite=Lax protection. Users should urgently upgrade to version 0.3.3.
Azərbaycanca: CVE-2026-47725 nebula-mesh öz-özünə host edilən idarəetmə panelində aşkar edilmiş boşluqdur. Versiya 0.3.3-dən əvvəlki versiyalarda, /ui/* POST/PUT/PATCH/DELETE sorğuları yalnız session cookie ilə yoxlanılır və SameSite=Lax müdafiəsi bəzi hallarda yan keçilə bilər. Təsirə məruz qalan sistemlərdə istifadəçilər təcili olaraq 0.3.3 versiyasına yenilənmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What product is affected by CVE-2026-47725?
CVE-2026-47725 affects versions of nebula-mesh, the self-hosted control plane for Slack Nebula, prior to 0.3.3.
What should users do to protect against this vulnerability?
Users should urgently upgrade nebula-mesh to version 0.3.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.