{"id":"CVE-2026-50288","title":"@asymmetric-effort/specifyjs: URL parse failure silently allows request","summary":"@asymmetric-effort/specifyjs: URL parse failure silently allows request","severity":"high","cwe":["CWE-918"],"vendor":"asymmetric-effort","product":"@asymmetric-effort/specifyjs","ecosystem":"npm","affected":["@asymmetric-effort/specifyjs < 0.2.136"],"patched":["@asymmetric-effort/specifyjs 0.2.136"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-8882-frvv-92w4","references":[{"url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-8882-frvv-92w4"},{"url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a"},{"url":"https://github.com/asymmetric-effort/specifyjs/releases/tag/v0.2.136"},{"url":"https://github.com/advisories/GHSA-8882-frvv-92w4"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T19:41:50.964Z","epss":0.00276,"epssPercentile":0.20295,"slug":"CVE-2026-50288","body":"## Overview\n\n## Finding\n\n**Location**: `core/src/shared/secure-fetch.ts:42-45`\n\nWhen `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation.\n\n## Status\n\n**Fixed in v0.2.136** — The catch block now throws an error instead of silently returning.\n\n## Affected packages\n\n- `@asymmetric-effort/specifyjs < 0.2.136`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@asymmetric-effort/specifyjs 0.2.136`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}