CVE-2026-44204

MEDIUM

Shelf: SQL Injection via sortBy Parameter

Title source: cna
STIX 2.1

Description

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to other organizations. This vulnerability is fixed in 1.20.1.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 13.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-89
Status published
Products (1)
Shelf-nu/shelf.nu >= 1.12, < 1.20.1
Published May 12, 2026
Tracked Since May 13, 2026