highVulnerability

CVE-2026-50288

## Finding **Location**: `core/src/shared/secure-fetch.ts:42-45` When `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. ## Status **Fixed in v0.2.136** — The catch block now throws an error instead of silently returning.

Properties

ghsa_id
GHSA-8882-frvv-92w4
summary
@asymmetric-effort/specifyjs: URL parse failure silently allows request
severity
high
cve_id
CVE-2026-50288
is_ghsa_only
false
ghsa_published
2026-07-02T18:59:33Z
source_url
https://github.com/advisories/GHSA-8882-frvv-92w4
ghsa_updated
2026-07-02T18:59:33Z

Related Entities (4)

AFFECTS (1)

[Software]npm/@asymmetric-effort/specifyjs

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@asymmetric-effort/specifyjs

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-50288 — Ninja Signal Threat Intelligence | Ninja Signal