PT-2026-57601 · Npm · @Asymmetric-Effort/Specifyjs

Published

2026-07-02

·

Updated

2026-07-02

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Finding

Location: core/src/core/scheduler.ts:23, core/src/hooks/dispatcher.ts:100, core/src/client/graphql.ts:71
Several console.warn calls are not gated behind DEV and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.

Status

Open — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.

Recommendation

Gate all development-time console.warn and console.error calls behind process.env.NODE ENV !== 'production' or a DEV constant that build tools can tree-shake.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-QCR8-X557-7CP3

Affected Products

@Asymmetric-Effort/Specifyjs