4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
Description
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Basic Information
ID
CVE-2025-62820
Source
mitre
Published
Oct 23, 2025 at 00:00
Modified
Oct 23, 2025 at 03:57
Affected Product
Vendor
Slack
Product
Nebula
Affected Versions
Slack Nebula 0