CVE-2026-50290EPSS p40.0%
CVE-2026-50290CVE-2026-50290
Description
SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\65xpression(`), null bytes, or CSS comments (`exp/**/ression(`). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for `behavior:`, `-moz-binding`, and `-o-link` patterns.
Scoring
| EPSS | 0.49% probability of exploitation · percentile 40.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |