---
id: GHSA-qcr8-x557-7cp3
title: >-
  @asymmetric-effort/specifyjs: Production console warnings may leak internal
  framework state
summary: >-
  @asymmetric-effort/specifyjs: Production console warnings may leak internal
  framework state
severity: medium
cwe:
  - CWE-209
vendor: asymmetric-effort
product: '@asymmetric-effort/specifyjs'
ecosystem: npm
affected:
  - '@asymmetric-effort/specifyjs <= 0.2.137'
patched:
  - '@asymmetric-effort/specifyjs 0.2.140'
published: '2026-07-02'
updated: '2026-07-02'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-qcr8-x557-7cp3'
references:
  - url: >-
      https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-qcr8-x557-7cp3
  - url: >-
      https://github.com/asymmetric-effort/specifyjs/commit/2ef791bc73ead853efd0c227ad8228bc594a7b63
  - url: 'https://github.com/advisories/GHSA-qcr8-x557-7cp3'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-02T19:41:50.960Z'
---

## Overview

## Finding

**Location**: `core/src/core/scheduler.ts:23`, `core/src/hooks/dispatcher.ts:100`, `core/src/client/graphql.ts:71`

Several `console.warn` calls are not gated behind `__DEV__` and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.

## Status

**Open** — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.

## Recommendation

Gate all development-time `console.warn` and `console.error` calls behind `process.env.NODE_ENV !== 'production'` or a `__DEV__` constant that build tools can tree-shake.

## Affected packages

- `@asymmetric-effort/specifyjs <= 0.2.137`

## Remediation

Upgrade to a patched release:

- `@asymmetric-effort/specifyjs 0.2.140`
