Executive brief
A vulnerability was identified in the specifyjs library's secure fetching mechanism, which is used to safely retrieve data from external sources. The library failed to block certain local network addresses, such as IPv6 loopback and specific local IP ranges, which could allow an attacker to bypass security restrictions and interact with services running on the local server. This could lead to unauthorized internal requests or data manipulation within the local environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in `@asymmetric-effort/specifyjs` within the `core/src/shared/secure-fetch.ts` component. The implementation of the localhost exception filter was incomplete, only explicitly blocking `localhost` and `127.0.0.1`. It failed to account for alternative loopback representations including `0.0.0.0`, the IPv6 loopback address `[::1]`, and the broader `127.0.0.0/8` range. An attacker can exploit this to bypass intended network restrictions and reach internal services. The issue is fixed in version 0.2.136 by expanding the detection logic to cover these additional ranges.
Affected products
- asymmetric-effort specifyjs < 0.2.136
Timeline
- 2026-05-29: patched: Fix included in version 0.2.136.
- 2026-07-02: advisory: GitHub Advisory GHSA-xw57-23p8-9wc5 published.
References
- https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-xw57-23p8-9wc5
- https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a
- https://github.com/asymmetric-effort/specifyjs/commit/293124c51bf797c0f5cdae32981110545850a893
- https://api.github.com/repos/asymmetric-effort/specifyjs/security-advisories/GHSA-xw57-23p8-9wc5