High severityNVD Advisory· Published Jul 2, 2026
@asymmetric-effort/specifyjs: URL parse failure silently allows request
CVE-2026-50288
Description
Finding
Location: core/src/shared/secure-fetch.ts:42-45
When new URL() throws a parse error, the assertSecureUrl function returned without throwing, silently allowing the request to proceed without HTTPS validation.
Status
Fixed in v0.2.136 — The catch block now throws an error instead of silently returning.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@asymmetric-effort/specifyjsnpm | < 0.2.136 | 0.2.136 |
Affected products
1- Range: <0.2.136
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.