SQL Injection Vulnerability in Shelf Platform for Asset Tracking by Shelf
CVE-2026-44204
6.5MEDIUM
What is CVE-2026-44204?
The Shelf platform, utilized for tracking physical assets, has a significant SQL injection vulnerability that affects versions from 1.12 up to but not including 1.20.1. This flaw resides in the 'sortBy' query parameter on the /assets route, which allows any authenticated user, regardless of role, to execute arbitrary SQL queries. Consequently, this could lead to unauthorized access to sensitive data across different database tables, including information belonging to other organizations. This vulnerability has been addressed in version 1.20.1.
Affected Version(s)
shelf.nu >= 1.12, < 1.20.1
