Junglewise Threat Intelligence

CVE-2026-44425: ShellHub field injection in device list endpoint

CVE-2026-44425 · Severity: medium · CVSS 5.4 · Published 2026-05-13

Technologies: github.com/shellhub-io/shellhub (Go), ShellHub. Vendors: Go, ShellHub.

Executive brief

ShellHub is a centralized gateway used to manage and access remote servers via SSH. A vulnerability in the device listing feature allows logged-in users to send specially crafted database queries that cause the system to crash or return errors. This can be used to disrupt service availability, flood system logs with errors, or potentially slow down the database through complex search requests.

Technical details

A field injection vulnerability exists in ShellHub's device list endpoint due to improper validation of user-supplied keys in the 'filter' (base64-encoded) and 'sort_by' query parameters. These values are passed directly as BSON keys in the MongoDB aggregation pipeline within 'api/store/mongo/query-options.go'. An authenticated attacker can inject MongoDB operators (e.g., $where, $regex) or internal field names to trigger server-side errors (HTTP 500), cause log exhaustion, or perform blind regex extraction. The lack of rate limiting on these requests further facilitates resource exhaustion or ReDoS attacks on large datasets. The issue is resolved in version 0.24.2 by implementing stricter input validation.

Affected products

  • ShellHub ShellHub < 0.24.2

Timeline

  • 2026-04-29: advisory: GitHub Security Advisory published by vendor
  • 2026-05-13: disclosed: CVE published to NVD
  • 2026-05-13: patched: Fix confirmed in version 0.24.2

References

Related threats