CVE-2026-47722 | forgekeep nebula-mesh up to 0.3.1 Config Generator/Web advanced.go ListenHost/TunDevice code injection
A vulnerability was found in forgekeep nebula-mesh up to 0.3.1. It has been declared as very critical. Impacted is an unknown function of the file internal/configgen/generator.go/internal/web/advanced.go of the component Config Generator/Web Handler. The manipulation of the argument ListenHost/TunDevice results in code injection.
This vulnerability is cataloged as CVE-2026-47722. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More