Junglewise Threat Intelligence

CVE-2026-47722: Forgekeep nebula-mesh YAML injection in agent config generator

CVE-2026-47722 · Severity: high · CVSS 4 · Published 2026-07-23

Technologies: Forgekeep Nebula-Mesh, github.com/juev/nebula-mesh (Go). Vendors: Forgekeep, Go.

Executive brief

Nebula-mesh is a management tool for Slack Nebula virtual private networks. A security flaw allowed users with basic access to inject malicious configuration settings into the system. This could allow an attacker to take control of network traffic, promote their own devices to central network hubs (lighthouses), or intercept data from other users on the mesh network.

Technical details

A YAML injection vulnerability exists in nebula-mesh prior to version 0.3.2. The `internal/configgen/generator.go` component used `text/template` to interpolate operator-supplied fields like `ListenHost` and `TunDevice` directly into the agent's `config.yml` without proper validation or escaping. An attacker with operator-level access can provide specially crafted strings containing newlines and YAML structural characters to inject arbitrary configuration keys. This allows for privilege escalation, such as self-promoting a node to a lighthouse or relay, potentially intercepting or redirecting mesh traffic. The issue was resolved by migrating from string-based templates to typed-struct marshalling using `yaml.v3`.

Affected products

  • forgekeep nebula-mesh < 0.3.2

Timeline

  • 2026-05-20: disclosed: Initial advisory published on GitHub
  • 2026-05-21: patched: Fix committed to main branch
  • 2026-07-23: advisory: CVE published to NVD

References

Related threats