Dismissed
(no matching packages found)
Permalink
CVE-2026-47768
5.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created & dismissed (no matching packages found) suggestion
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.
References
-
https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-9pg3-25fq-p6cc x_refsource_CONFIRM
-
https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2 x_refsource_MISC
Affected products
nebula-mesh
- ==< 0.3.2