Impact
Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the asset:import permission can trigger server‑side HTTP requests to attacker‑controlled URLs through theUrl" validation logic including image‑extension suffixes, image‑related path keywords, domain substring matching, and redirect chains. After validation, the server performs an unrestricted fetch() request to the supplied URL. This results in a Server‑Side Request Forgery (SSRF) vulnerability that allows attackers to reach internal network services, cloud metadata endpoints, and arbitrary external hosts from the application's network context. Additionally, response bodies are fully buffered before size validation, creating a potential memory exhaustion vector. Version 1.20.3 patches the issue.
Affected Systems
The Shelf platform, hosted at shelf.nu by Shelf‑nu, is affected. Any installation running a version earlier than 1.20.3, and where users possess the asset:import permission, is vulnerable. The patch that fixes the vulnerability is available in Shelf version 1.20.3 and newer.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% shows the overall likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. However, the flaw requires only authenticated access with the asset:import role and can be leveraged to probe internal services, exfiltrate data, or launch memory‑stress attacks via large response bodies. Once exploited, an attacker can effectively pivot within the network from the application’s outbound connection point.
OpenCVE Enrichment