PT-2026-55465 · Npm+2 · @Asymmetric-Effort/Specifyjs+1

CVE-2026-50288

·

Published

2026-07-02

·

Updated

2026-08-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SpecifyJS versions prior to 0.2.136
Description In the assertSecureUrl() function, a parse error triggered by new URL() caused the function to return without throwing an exception. This behavior allowed requests to proceed without the required HTTPS validation.
Recommendations Update to version 0.2.136 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50288
GHSA-8882-FRVV-92W4

Affected Products

@Asymmetric-Effort/Specifyjs
Specifyjs