Executive brief
SpecifyJS, a JavaScript library used for web development, contains a vulnerability in its server-side rendering component. An attacker could bypass security filters to inject malicious CSS code. While this primarily affects users on older web browsers (like Internet Explorer 6-10), it could potentially lead to unauthorized script execution in those environments.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the `renderToString` function of `@asymmetric-effort/specifyjs` due to insufficient sanitization of CSS values. The original implementation used simple regular expressions to strip `expression(` and `url(javascript:`, which could be bypassed using CSS unicode escapes (e.g., `\65xpression(`), null bytes, or CSS comments. While modern browsers are not susceptible to these specific CSS-based execution vectors, legacy browsers (IE6-IE10) may execute the injected code. The vulnerability was fixed in version 0.2.136 by normalizing unicode escapes and stripping comments before pattern matching.
Affected products
- asymmetric-effort @asymmetric-effort/specifyjs < 0.2.136
Timeline
- 2026-05-29: disclosed: Vulnerability identified during penetration test code review
- 2026-05-29: patched: Fixed in version 0.2.136
- 2026-07-02: advisory: GitHub Advisory published