CVE-2026-50288
Last modified
CVE-2026-50288 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation.
Description
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| asymmetric-effort | specifyjs | < 0.2.136 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-50288?
How severe is CVE-2026-50288?
How do I fix CVE-2026-50288?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50281Craft CMS is a content management system (CMS). Versions 5.7…7.1
- CVE-2026-50282Craft CMS is a content management system (CMS). Versions 5.0…4.9
- CVE-2026-50283Craft CMS is a content management system (CMS). Versions 5.0…5.3
- CVE-2026-50284Craft CMS is a content management system (CMS). In versions …7.1
- CVE-2026-50285Pomerium is an identity and context-aware access proxy. Prio…7.5
- CVE-2026-50287AgenticMail gives AI agents real email addresses and phone n…8.7
- CVE-2026-50289systeminformation is a System and OS information library for…8.8
- CVE-2026-5029A remote code execution vulnerability exists in Code Runner …8.7
- CVE-2026-50290SpecifyJS is a declarative TypeScript user interface framewo…5.3
- CVE-2026-50291OpenImageIO is a toolset for reading, writing, and manipulat…5.5
- CVE-2026-50292In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput…9.8
- CVE-2026-50293Use after free in Windows Internal Task Bar allows an author…7.8
Are you affected by CVE-2026-50288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
