CVE-2026-50290
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\65xpression(`), null bytes, or CSS comments (`exp/**/ression(`). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for `behavior:`, `-moz-binding`, and `-o-link` patterns.
| CWE | CWE-79 |
| Vendor | asymmetric-effort |
| Product | specifyjs |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for asymmetric-effort specifyjs
Be the first to know when new unknown vulnerabilities affecting asymmetric-effort specifyjs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
asymmetric-effort / specifyjs
< 0.2.136