Vulnerabilities/

@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

Severity:
Medium

Description

Location: core/src/server/render-to-string.ts:307-311

CSS value sanitization stripped expression( and url(javascript: using simple regex, but could be bypassed with CSS unicode escapes (\65xpression(), null bytes, or CSS comments (exp/**/ression().

Recommendation

Update the @asymmetric-effort/specifyjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@asymmetric-effort/specifyjs
Anything's wrong? Let us know Last updated on July 02, 2026