CVE-2026-50288
@asymmetric-effort/specifyjs: URL parse failure silently allows request
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.
| CWE | CWE-918 |
| Vendor | asymmetric-effort |
| Product | specifyjs |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for asymmetric-effort specifyjs
Be the first to know when new unknown vulnerabilities affecting asymmetric-effort specifyjs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
asymmetric-effort / specifyjs
< 0.2.136