{"id":"CVE-2026-50288","aliases":["GHSA-8882-frvv-92w4"],"url":"https://o3.security/vulnerability/CVE-2026-50288","summary":"@asymmetric-effort/specifyjs: URL parse failure silently allows request","details":"SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.","published":"2026-08-21T19:29:45.774Z","modified":"2026-08-23T03:53:39.246864785Z","cvss":null,"epss":{"score":0.00276,"percentile":0.1977,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@asymmetric-effort/specifyjs","fixedVersion":"0.2.136"}],"fix":{"url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a","label":"asymmetric-effort/specifyjs@25d1fb4"},"references":[{"type":"WEB","url":"https://github.com/asymmetric-effort/specifyjs/releases/tag/v0.2.136"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50288.json"},{"type":"ADVISORY","url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-8882-frvv-92w4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50288"},{"type":"FIX","url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:53:39.246864785Z"}}