PT-2026-57601 · Npm · @Asymmetric-Effort/Specifyjs
Published
2026-07-02
·
Updated
2026-07-02
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Finding
Location:
core/src/core/scheduler.ts:23, core/src/hooks/dispatcher.ts:100, core/src/client/graphql.ts:71Several
console.warn calls are not gated behind DEV and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.Status
Open — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.
Recommendation
Gate all development-time
console.warn and console.error calls behind process.env.NODE ENV !== 'production' or a DEV constant that build tools can tree-shake.Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Asymmetric-Effort/Specifyjs