Impact
Based on the description, it is inferred that nebula‑mesh exposes all web UI and API responses without standard browser‑security headers such as CSP, X-Frame-Options, Strict-Transport-Security, X-Content-Type-Options, or Referrer‑Policy. The absence of these headers can enable click‑jacking, iframe injection, insecure content loading, and allow attackers to downgrade transport security or inject malicious scripts, thereby potentially compromising the confidentiality and integrity of data transmitted to authenticated users.
Affected Systems
The affected product is the self‑hosted control plane for the Slack Nebula Mesh VPN called nebula‑mesh, provided by the vendor juev. All releases prior to 0.3.1 are vulnerable; version 0.3.1 and later include the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% indicates that the likelihood of exploitation is currently very low and it is not listed in the CISA KEV catalogue. Based on the description, it is inferred that attackers can exploit the flaw remotely by interacting with the web UI or API endpoints, since the responses are served directly by nebula‑mesh without additional security layers. Based on the description, it is inferred that an attacker who obtains a user session or can perform a man‑in‑the‑middle attack could include malicious iframes, strip security headers, or cause a browser to load insecure content, potentially leading to data leakage or credential compromise.
OpenCVE Enrichment
Github GHSA