Executive brief
A vulnerability in the SpecifyJS library could allow network requests to bypass security checks. The library is designed to enforce secure HTTPS connections, but certain malformed web addresses could cause the validation process to fail silently, allowing potentially insecure or unauthorized requests to proceed. This could lead to unauthorized data access or internal network requests.
Technical details
A vulnerability exists in the `assertSecureUrl` function within `core/src/shared/secure-fetch.ts`. When the `new URL()` constructor throws a parse error, the function's catch block returns silently instead of throwing an exception. This behavior allows the request to proceed without completing the intended HTTPS and security validation checks. An attacker can exploit this by providing malformed URLs that trigger a parsing error but are still processed by the underlying fetch mechanism, potentially leading to Server-Side Request Forgery (SSRF). The issue is fixed in version 0.2.136 by ensuring the catch block properly throws an error.
Affected products
- asymmetric-effort @asymmetric-effort/specifyjs < 0.2.136
Timeline
- 2026-05-29: patched: Fix included in version 0.2.136
- 2026-07-02: advisory: GitHub Advisory published
References
- https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-8882-frvv-92w4
- https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a
- https://github.com/asymmetric-effort/specifyjs/releases/tag/v0.2.136
- https://api.github.com/repos/asymmetric-effort/specifyjs/security-advisories/GHSA-8882-frvv-92w4