Vulnerabilities/

@asymmetric-effort/specifyjs: URL parse failure silently allows request

Severity:
High

Description

Location: core/src/shared/secure-fetch.ts:42-45

When new URL() throws a parse error, the assertSecureUrl function returned without throwing, silently allowing the request to proceed without HTTPS validation.

Recommendation

Update the @asymmetric-effort/specifyjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@asymmetric-effort/specifyjs
Anything's wrong? Let us know Last updated on July 02, 2026