Executive brief
SpecifyJS is a JavaScript library used to build data-driven user interfaces. The secureFetch function validates the initial request URL but fails to validate redirect targets, allowing an attacker to redirect a request from a valid HTTPS endpoint to an internal service or other unvalidated destination. This could lead to server-side request forgery attacks and exposure of internal services.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) via HTTP redirect in the secureFetch function located in core/src/shared/secure-fetch.ts. The assertSecureUrl validation only checks the initial request URL but does not validate redirect targets; the fetch() API follows redirects by default (up to 20 hops). An attacker can craft a response that redirects from a validated HTTPS URL to an internal service (e.g., http://internal-service/) or other unvalidated destination, causing the application to make requests to unintended targets. The fix, implemented in v0.2.136, changes the default behavior to redirect: 'error' which rejects any redirect, while allowing callers to explicitly opt into following redirects via { redirect: 'follow' } if they trust the target.
Affected products
- asymmetric-effort specifyjs <0.2.136
Timeline
- 2026-07-02: disclosed
- 2026-05-29: patched: Fixed in v0.2.136