@asymmetric-effort/specifyjs vulnerabilities
CVEs whose affected-version data names the @asymmetric-effort/specifyjs package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-50288High@asymmetric-effort/specifyjs: URL parse failure silently allows request
@asymmetric-effort/specifyjs: URL parse failure silently allows request
GHSA-5c7w-4wm3-85vwMedium@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
GHSA-qcr8-x557-7cp3Medium@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-2944-57xv-2682Medium@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
GHSA-j5qp-p44g-2m49Medium@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
CVE-2026-50290Medium@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString