VYPR
Medium severity6.5NVD Advisory· Published May 12, 2026· Updated May 14, 2026

CVE-2026-44204

CVE-2026-44204

Description

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to other organizations. This vulnerability is fixed in 1.20.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Shelf Nu/Shelf.nureferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: >=1.12, <1.20.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.