CVE-2026-50288High▾ Twilight@asymmetric-effort/specifyjs: URL parse failure silently allows request
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Location: core/src/shared/secure-fetch.ts:42-45
When new URL() throws a parse error, the assertSecureUrl function returned without throwing, silently allowing the request to proceed without HTTPS validation.
Fixed in v0.2.136 — The catch block now throws an error instead of silently returning.
@asymmetric-effort/specifyjs < 0.2.136Upgrade to a patched release:
@asymmetric-effort/specifyjs 0.2.136Connected by shared product, vendor, weakness, or advisory.
GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-2944-57xv-2682Medium@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
GHSA-j5qp-p44g-2m49Medium@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
GHSA-5c7w-4wm3-85vwMedium@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
CVE-2026-50290Medium@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
GHSA-qcr8-x557-7cp3Medium@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state