CVE-2026-54166

Source
https://cve.org/CVERecord?id=CVE-2026-54166
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54166.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54166
Aliases
  • GHSA-xgrm-8w6v-mvjg
Published
2026-09-11T21:06:57Z
Modified
2026-09-13T03:30:51Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L CVSS Calculator
Summary
Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass
Details

Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the asset:import permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feature. The imageUrl validation logic can be bypassed through multiple techniques, including image-extension suffixes, image-related path keywords, domain substring matching, and redirect chains. After validation, the server performs an unrestricted fetch() request to the supplied URL. This results in a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to reach internal network services, cloud metadata endpoints, and arbitrary external hosts from the application's network context. Additionally, response bodies are fully buffered before size validation, creating a potential memory exhaustion vector. Version 1.20.3 patches the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54166.json"
}
References

Affected packages

Git / github.com/shelf-nu/shelf.nu

Affected ranges

Type
GIT
Repo
https://github.com/shelf-nu/shelf.nu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.20.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

shelf@1.*
shelf@1.0.0
shelf@1.1.0
shelf@1.1.1
shelf@1.1.2
shelf@1.10.1
shelf@1.10.10
shelf@1.10.2
shelf@1.10.3
shelf@1.10.4
shelf@1.10.5
shelf@1.10.6
shelf@1.10.7
shelf@1.10.8
shelf@1.10.9
shelf@1.11.0
shelf@1.11.1
shelf@1.11.2
shelf@1.11.3
shelf@1.11.4
shelf@1.11.5
shelf@1.12
shelf@1.12.1
shelf@1.12.2
shelf@1.12.3
shelf@1.12.4
shelf@1.12.5
shelf@1.12.6
shelf@1.13.0
shelf@1.13.1
shelf@1.14.0
shelf@1.14.1
shelf@1.14.2
shelf@1.14.3
shelf@1.15.0
shelf@1.15.1
shelf@1.16.0
shelf@1.16.1
shelf@1.16.2
shelf@1.16.3
shelf@1.16.4
shelf@1.17.0
shelf@1.17.1
shelf@1.17.2
shelf@1.18.0
shelf@1.18.1
shelf@1.18.2
shelf@1.18.3
shelf@1.18.4
shelf@1.18.5
shelf@1.18.6
shelf@1.19.0
shelf@1.2.0
shelf@1.2.1
shelf@1.2.10
shelf@1.2.2
shelf@1.2.3
shelf@1.2.4
shelf@1.2.5
shelf@1.2.6
shelf@1.2.7
shelf@1.2.8
shelf@1.2.9
shelf@1.20.0
shelf@1.20.1
shelf@1.20.2
shelf@1.3.0
shelf@1.3.1
shelf@1.4.0
shelf@1.4.1
shelf@1.5.0
shelf@1.5.1
shelf@1.5.2
shelf@1.5.3
shelf@1.5.4
shelf@1.6.0
shelf@1.6.1
shelf@1.6.2
shelf@1.7.0
shelf@1.7.1
shelf@1.7.2
shelf@1.7.3
shelf@1.8.0
shelf@1.8.1
shelf@1.8.2
shelf@1.9.0
shelf@1.9.1
shelf@1.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54166.json"