VYPR
Medium severityNVD Advisory· Published Jul 2, 2026

@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

CVE-2026-50290

Description

Finding

Location: core/src/server/render-to-string.ts:307-311

CSS value sanitization stripped expression( and url(javascript: using simple regex, but could be bypassed with CSS unicode escapes (\65xpression(), null bytes, or CSS comments (exp/**/ression().

Mitigating Factor: These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers.

Status

Fixed in v0.2.136 — CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for behavior:, -moz-binding, and -o-link patterns.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@asymmetric-effort/specifyjsnpm
< 0.2.1360.2.136

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.