Junglewise Threat Intelligence

CVE-2026-50288: SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assert

CVE-2026-50288 · Severity: high · CVSS 4 · Published 2026-08-21

Technologies: Asymmetric Effort Specifyjs, @asymmetric-effort/specifyjs (npm). Vendors: Asymmetric Effort, npm.

Executive brief

A vulnerability in the SpecifyJS library could allow network requests to bypass security checks. The library is designed to enforce secure HTTPS connections, but certain malformed web addresses could cause the validation process to fail silently, allowing potentially insecure or unauthorized requests to proceed. This could lead to unauthorized data access or internal network requests.

Technical details

A vulnerability exists in the `assertSecureUrl` function within `core/src/shared/secure-fetch.ts`. When the `new URL()` constructor throws a parse error, the function's catch block returns silently instead of throwing an exception. This behavior allows the request to proceed without completing the intended HTTPS and security validation checks. An attacker can exploit this by providing malformed URLs that trigger a parsing error but are still processed by the underlying fetch mechanism, potentially leading to Server-Side Request Forgery (SSRF). The issue is fixed in version 0.2.136 by ensuring the catch block properly throws an error.

Affected products

  • asymmetric-effort @asymmetric-effort/specifyjs < 0.2.136

Timeline

  • 2026-05-29: patched: Fix included in version 0.2.136
  • 2026-07-02: advisory: GitHub Advisory published

References

Related threats