ShellHub has cross-tenant IDOR in GET /api/namespaces/:tenant via API Key bypasses membership check in github.com/shellhub-io/shellhub
GET /api/namespaces/:tenant
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-5680" }
"https://vuln.go.dev/ID/GO-2026-5680.json"