Cross-Site Request Forgery Vulnerability in nebula-mesh by Forgekeep
CVE-2026-47725

6.9MEDIUM

Key Information:

Vendor

Juev

Vendor
CVE Published:
28 July 2026

What is CVE-2026-47725?

The nebula-mesh control plane for Slack suffers from a cross-site request forgery vulnerability. Prior to version 0.3.3, requests to all /ui/* POST, PUT, PATCH, and DELETE routes were processed immediately upon successful session cookie validation. Although the session cookie uses SameSite=Lax, it does not adequately protect against cross-origin top-level form submissions or attacks from same-registrable-domain entities such as sibling-subdomain XSS or subdomain takeover. Additionally, the /ui/logout route could be exploited via a third-party image request. Users are advised to upgrade to version 0.3.3 to mitigate these risks.

Affected Version(s)

nebula-mesh < 0.3.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.