CVE-2026-50288

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 20:16

Updated : 2026-08-21 20:16


NVD link : CVE-2026-50288

Mitre link : CVE-2026-50288

CVE.ORG link : CVE-2026-50288


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)