Security: Shelf-nu/shelf.nu
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Cross-organization IDOR: audit note content could be read and overwritten across workspaces (broken object-level authorization)GHSA-j83g-fjxm-w7m7 published
Aug 20, 2026 by DonKokoHigh -
Password-reset OTPs and user-chosen passwords were written to server logs in plaintextGHSA-wc84-38wc-wchr published
Aug 19, 2026 by DonKokoModerate -
Server-Side Request Forgery (SSRF) via the Sentry tunnel endpoint's client-controlled DSNGHSA-mgp7-gf45-fxqg published
Aug 19, 2026 by DonKokoHigh -
Invite acceptance acted on the token's invite rather than the one displayed, allowing a victim to be signed in as the attacker's userGHSA-f3w7-26qj-w72r published
Aug 19, 2026 by DonKokoHigh -
Cross-organization IDOR: authenticated users could delete another workspace's notes, working-hours overrides and audit assets (broken object-level authorization)GHSA-m9ch-h468-7mh9 published
Aug 19, 2026 by DonKokoHigh -
Audit image evidence readable and deletable by workspace members not assigned to the audit (broken object-level authorization)GHSA-433r-fpjf-cc4h published
Aug 20, 2026 by DonKokoModerate -
Workspace Administrators can seize or revoke workspace ownership (broken access control)GHSA-r374-4wpq-9cqx published
Aug 17, 2026 by DonKokoModerate -
Self Service members can release custody on kits held by other members (broken access control)GHSA-59xr-h3v6-74hf published
Aug 14, 2026 by DonKokoHigh -
Custody identity and member personal data disclosed to low-privilege workspace membersGHSA-jwvm-658j-g7p7 published
Aug 14, 2026 by DonKokoModerate -
Booking bulk actions missing object-level authorization allows same-organization users to modify or delete other users' bookingsGHSA-vwgm-wmh3-8x9c published
Aug 17, 2026 by DonKokoModerate
Learn more about advisories related to Shelf-nu/shelf.nu in the GitHub Advisory Database