nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
Published Jul 23, 2026
8.7
HIGHCVSS 4.0
EPSS 0.47%
Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation. Version 0.3.2 fixes the issue.
Affected products
-
Affected
- < 0.3.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Juev | Nebula-Mesh | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/juev/nebula-mesh
Go
Introduced 0 Fixed 0.3.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/juev/nebula-mesh | 0 | 0.3.2 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48381 Advisory
- https://github.com/advisories/GHSA-7hp6-g3pq-3pc3 Advisory
- https://github.com/forgekeep/nebula-mesh/commit/c1506f7344ab375a145a7449b193af3f19bb41ef x_refsource_MISC
- https://github.com/forgekeep/nebula-mesh/issues/126 x_refsource_MISC
- https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7hp6-g3pq-3pc3 x_refsource_CONFIRM
- https://github.com/juev/nebula-mesh/security/advisories/GHSA-7hp6-g3pq-3pc3
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub