Cross-Site Request Forgery Vulnerability in nebula-mesh by Forgekeep
CVE-2026-47725
6.9MEDIUM
What is CVE-2026-47725?
The nebula-mesh control plane for Slack suffers from a cross-site request forgery vulnerability. Prior to version 0.3.3, requests to all /ui/* POST, PUT, PATCH, and DELETE routes were processed immediately upon successful session cookie validation. Although the session cookie uses SameSite=Lax, it does not adequately protect against cross-origin top-level form submissions or attacks from same-registrable-domain entities such as sibling-subdomain XSS or subdomain takeover. Additionally, the /ui/logout route could be exploited via a third-party image request. Users are advised to upgrade to version 0.3.3 to mitigate these risks.
Affected Version(s)
nebula-mesh < 0.3.3
