mediumVulnerability
GHSA-2944-57xv-2682
## Finding **Location**: `core/src/shared/secure-fetch.ts:33-35` `data:` URIs were allowed without any restriction. While `data:` URIs don't make network requests, they can be used for memory exhaustion via very large data URIs. ## Status **Fixed in v0.2.136** — `data:` URIs are now limited to 1MB. URIs exceeding this limit throw an error.
Properties
- ghsa_id
- GHSA-2944-57xv-2682
- severity
- medium
- summary
- @asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
- cve_id
- GHSA-2944-57xv-2682
- is_ghsa_only
- true
- ghsa_published
- 2026-07-02T19:07:44Z
- source_url
- https://github.com/advisories/GHSA-2944-57xv-2682
- ghsa_updated
- 2026-07-02T19:07:45Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/@asymmetric-effort/specifyjs
HAS_WEAKNESS (1)
→[Weakness]Server-Side Request Forgery (SSRF)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/@asymmetric-effort/specifyjs
Explore deeper with Ninja Signal's threat intelligence graph