Junglewise Threat Intelligence

CVE-2026-50290: SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and

CVE-2026-50290 · Severity: medium · CVSS 4 · Published 2026-08-21

Technologies: Asymmetric Effort Specifyjs, @asymmetric-effort/specifyjs (npm). Vendors: Asymmetric Effort, npm.

Executive brief

SpecifyJS, a JavaScript library used for web development, contains a vulnerability in its server-side rendering component. An attacker could bypass security filters to inject malicious CSS code. While this primarily affects users on older web browsers (like Internet Explorer 6-10), it could potentially lead to unauthorized script execution in those environments.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the `renderToString` function of `@asymmetric-effort/specifyjs` due to insufficient sanitization of CSS values. The original implementation used simple regular expressions to strip `expression(` and `url(javascript:`, which could be bypassed using CSS unicode escapes (e.g., `\65xpression(`), null bytes, or CSS comments. While modern browsers are not susceptible to these specific CSS-based execution vectors, legacy browsers (IE6-IE10) may execute the injected code. The vulnerability was fixed in version 0.2.136 by normalizing unicode escapes and stripping comments before pattern matching.

Affected products

  • asymmetric-effort @asymmetric-effort/specifyjs < 0.2.136

Timeline

  • 2026-05-29: disclosed: Vulnerability identified during penetration test code review
  • 2026-05-29: patched: Fixed in version 0.2.136
  • 2026-07-02: advisory: GitHub Advisory published

References

Related threats