CVE-2026-50288: Asymmetric-Effort Specifyjs

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.

Affected products

Published 2026-08-21. Last modified 2026-09-30.