highVulnerability
CVE-2026-50288
## Finding **Location**: `core/src/shared/secure-fetch.ts:42-45` When `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. ## Status **Fixed in v0.2.136** — The catch block now throws an error instead of silently returning.
Properties
- ghsa_id
- GHSA-8882-frvv-92w4
- summary
- @asymmetric-effort/specifyjs: URL parse failure silently allows request
- severity
- high
- cve_id
- CVE-2026-50288
- is_ghsa_only
- false
- ghsa_published
- 2026-07-02T18:59:33Z
- source_url
- https://github.com/advisories/GHSA-8882-frvv-92w4
- ghsa_updated
- 2026-07-02T18:59:33Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/@asymmetric-effort/specifyjs
HAS_WEAKNESS (1)
→[Weakness]Server-Side Request Forgery (SSRF)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/@asymmetric-effort/specifyjs
Explore deeper with Ninja Signal's threat intelligence graph