Medium severityNVD Advisory· Published Aug 21, 2026· Updated Aug 21, 2026
CVE-2026-50290
CVE-2026-50290
Description
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped expression( and url(javascript: using simple regex, but could be bypassed with CSS unicode escapes (\65xpression(), null bytes, or CSS comments (exp/**/ression(). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for behavior:, -moz-binding, and -o-link patterns.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@asymmetric-effort/specifyjsnpm | < 0.2.136 | 0.2.136 |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.