{"id":"GHSA-qcr8-x557-7cp3","title":"@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state","summary":"@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state","severity":"medium","cwe":["CWE-209"],"vendor":"asymmetric-effort","product":"@asymmetric-effort/specifyjs","ecosystem":"npm","affected":["@asymmetric-effort/specifyjs <= 0.2.137"],"patched":["@asymmetric-effort/specifyjs 0.2.140"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qcr8-x557-7cp3","references":[{"url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-qcr8-x557-7cp3"},{"url":"https://github.com/asymmetric-effort/specifyjs/commit/2ef791bc73ead853efd0c227ad8228bc594a7b63"},{"url":"https://github.com/advisories/GHSA-qcr8-x557-7cp3"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T19:41:50.960Z","slug":"GHSA-qcr8-x557-7cp3","body":"## Overview\n\n## Finding\n\n**Location**: `core/src/core/scheduler.ts:23`, `core/src/hooks/dispatcher.ts:100`, `core/src/client/graphql.ts:71`\n\nSeveral `console.warn` calls are not gated behind `__DEV__` and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.\n\n## Status\n\n**Open** — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.\n\n## Recommendation\n\nGate all development-time `console.warn` and `console.error` calls behind `process.env.NODE_ENV !== 'production'` or a `__DEV__` constant that build tools can tree-shake.\n\n## Affected packages\n\n- `@asymmetric-effort/specifyjs <= 0.2.137`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@asymmetric-effort/specifyjs 0.2.140`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}