Description
Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feature. The `imageUrl` validation logic can be bypassed through multiple techniques, including image-extension suffixes, image-related path keywords, domain substring matching, and redirect chains. After validation, the server performs an unrestricted `fetch()` request to the supplied URL. This results in a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to reach internal network services, cloud metadata endpoints, and arbitrary external hosts from the application's network context. Additionally, response bodies are fully buffered before size validation, creating a potential memory exhaustion vector. Version 1.20.3 patches the issue.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the asset:import permission can trigger server‑side HTTP requests to attacker‑controlled URLs through theUrl" validation logic including image‑extension suffixes, image‑related path keywords, domain substring matching, and redirect chains. After validation, the server performs an unrestricted fetch() request to the supplied URL. This results in a Server‑Side Request Forgery (SSRF) vulnerability that allows attackers to reach internal network services, cloud metadata endpoints, and arbitrary external hosts from the application's network context. Additionally, response bodies are fully buffered before size validation, creating a potential memory exhaustion vector. Version 1.20.3 patches the issue.

Affected Systems

The Shelf platform, hosted at shelf.nu by Shelf‑nu, is affected. Any installation running a version earlier than 1.20.3, and where users possess the asset:import permission, is vulnerable. The patch that fixes the vulnerability is available in Shelf version 1.20.3 and newer.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% shows the overall likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. However, the flaw requires only authenticated access with the asset:import role and can be leveraged to probe internal services, exfiltrate data, or launch memory‑stress attacks via large response bodies. Once exploited, an attacker can effectively pivot within the network from the application’s outbound connection point.

Generated by OpenCVE AI on September 15, 2026 at 19:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Shelf platform to version 1.20.3 or later to remove the SSRF flaw
  • Revoke the asset:import permission from all users except those who absolutely need it, reducing the set of attackers who can trigger the flaw
  • Implement outbound firewall or proxy rules that block connections from the application to internal IP ranges and the cloud metadata service, preventing unintended internal access
  • Monitor application logs for unexpected fetch() requests or unusual outbound traffic as an early detection measure

Generated by OpenCVE AI on September 15, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Shelf-nu
Shelf-nu shelf.nu
Vendors & Products Shelf-nu
Shelf-nu shelf.nu

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feature. The `imageUrl` validation logic can be bypassed through multiple techniques, including image-extension suffixes, image-related path keywords, domain substring matching, and redirect chains. After validation, the server performs an unrestricted `fetch()` request to the supplied URL. This results in a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to reach internal network services, cloud metadata endpoints, and arbitrary external hosts from the application's network context. Additionally, response bodies are fully buffered before size validation, creating a potential memory exhaustion vector. Version 1.20.3 patches the issue.
Title Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Shelf-nu Shelf.nu
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:37:55.962Z

Reserved: 2026-06-11T21:46:52.380Z

Link: CVE-2026-54166

cve-icon Vulnrichment

Updated: 2026-09-14T18:37:52.123Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:11.247

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)