asymmetric-effort has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 9. None have a confirmed exploitation report. The most common weakness class is CWE-918 (4). Most affected products: @asymmetric-effort/specifyjs (7), @asymmetric-effort/nogginlessdom (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 9 prev 0
Weakness classes
Products
- @asymmetric-effort/specifyjs 7
- @asymmetric-effort/nogginlessdom 2
Worst active — by depth score
GHSA-322x-v876-g883High@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write41CVE-2026-50288High@asymmetric-effort/specifyjs: URL parse failure silently allows request41GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)28GHSA-x4hg-hfwf-p9mwMedium@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation28GHSA-qcr8-x557-7cp3Medium@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state28
asymmetric-effort vulnerabilities
CVEs affecting asymmetric-effort, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
GHSA-322x-v876-g883High@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
GHSA-x4hg-hfwf-p9mwMedium@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
CVE-2026-50288High@asymmetric-effort/specifyjs: URL parse failure silently allows request
@asymmetric-effort/specifyjs: URL parse failure silently allows request
GHSA-5c7w-4wm3-85vwMedium@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
GHSA-qcr8-x557-7cp3Medium@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-2944-57xv-2682Medium@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
GHSA-j5qp-p44g-2m49Medium@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
CVE-2026-50290Medium@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString