mediumVulnerability

GHSA-2944-57xv-2682

## Finding **Location**: `core/src/shared/secure-fetch.ts:33-35` `data:` URIs were allowed without any restriction. While `data:` URIs don't make network requests, they can be used for memory exhaustion via very large data URIs. ## Status **Fixed in v0.2.136** — `data:` URIs are now limited to 1MB. URIs exceeding this limit throw an error.

Properties

ghsa_id
GHSA-2944-57xv-2682
severity
medium
summary
@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
cve_id
GHSA-2944-57xv-2682
is_ghsa_only
true
ghsa_published
2026-07-02T19:07:44Z
source_url
https://github.com/advisories/GHSA-2944-57xv-2682
ghsa_updated
2026-07-02T19:07:45Z

Related Entities (4)

AFFECTS (1)

[Software]npm/@asymmetric-effort/specifyjs

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@asymmetric-effort/specifyjs

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2944-57xv-2682 — Ninja Signal Threat Intelligence | Ninja Signal