Vulnerability library
Security checkJuly 02, 2026

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Location: core/src/shared/secure-fetch.ts

assertSecureUrl validated only the initial request URL. The fetch() API follows redirects by default (up to 20 hops). A request to a valid https:// URL could redirect to http://internal-service/ or other unvalidated destinations.

Recommendation

Update the @asymmetric-effort/specifyjs package to the latest compatible version. Followings are version details:

  • Affected version(s): < 0.2.136
  • Patched version(s): 0.2.136

References

Could your website be exposed too?

SmartScanner can check your website for @asymmetric-effort/specifyjs: No redirect target validation in secureFetch and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 02, 2026