{"api_version":"v1","generated_at":"2026-10-06T20:55:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-shellhub-io-shellhub-e2818d14d16e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/shellhub","name":"shellhub","next_cursor":null,"observations":[{"affected":"< 0.24.2","affected_versions_present":true,"cve_id":"CVE-2026-44423","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44423","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T12:50:40.262Z","patch_url":"","primary_source":"","published":"2026-05-13T21:07:33.174Z"},{"affected":"< 0.24.2","affected_versions_present":true,"cve_id":"CVE-2026-44424","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44424","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T12:58:51.178Z","patch_url":"https://github.com/shellhub-io/shellhub/security/advisories/GHSA-j72x-xfwg-783f","primary_source":"","published":"2026-05-13T21:06:49.859Z"},{"affected":"< 0.24.2","affected_versions_present":true,"cve_id":"CVE-2026-44426","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44426","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T15:54:46.896Z","patch_url":"","primary_source":"","published":"2026-05-13T21:06:06.222Z"},{"affected":"< 0.24.2","affected_versions_present":true,"cve_id":"CVE-2026-44425","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44425","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T19:52:09.294Z","patch_url":"https://github.com/shellhub-io/shellhub/security/advisories/GHSA-47r2-v3x6-wff9","primary_source":"","published":"2026-05-13T21:05:07.925Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"shellhub-io"}}
