{"id":"CVE-2026-50290","aliases":["GHSA-93q6-wwjh-jc6h"],"url":"https://o3.security/vulnerability/CVE-2026-50290","summary":"@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString","details":"SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\\65xpression(`), null bytes, or CSS comments (`exp/**/ression(`). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for `behavior:`, `-moz-binding`, and `-o-link` patterns.","published":"2026-08-21T19:55:51.086Z","modified":"2026-08-23T03:53:39.246675586Z","cvss":null,"epss":{"score":0.00356,"percentile":0.2871,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@asymmetric-effort/specifyjs","fixedVersion":"0.2.136"}],"fix":{"url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a","label":"asymmetric-effort/specifyjs@25d1fb4"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50290.json"},{"type":"ADVISORY","url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-93q6-wwjh-jc6h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50290"},{"type":"FIX","url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:53:39.246675586Z"}}