@asymmetric-effort/specifyjs
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @asymmetric-effort/specifyjspage 1 of 1
- CVE-2026-50288HIGHCVSS 8.7EG 8.7✓ Fixed in 0.2.1362026-07-02
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTT…
- CVE-2026-50290MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.2.1362026-07-02
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\65xpression…
Check whether @asymmetric-effort/specifyjs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @asymmetric-effort/specifyjs CVEs against the assets you own.
Start Free Scan →