PT-2026-57601 · Npm · @Asymmetric-Effort/Specifyjs
Publicado
2026-07-02
·
Atualizado
2026-07-02
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Finding
Location:
core/src/core/scheduler.ts:23, core/src/hooks/dispatcher.ts:100, core/src/client/graphql.ts:71Several
console.warn calls are not gated behind DEV and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.Status
Open — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.
Recommendation
Gate all development-time
console.warn and console.error calls behind process.env.NODE ENV !== 'production' or a DEV constant that build tools can tree-shake.Correção
Generation of Error Message Containing Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
@Asymmetric-Effort/Specifyjs