{"id":"GHSA-qcr8-x557-7cp3","summary":"@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state","details":"## Finding\n\n**Location**: `core/src/core/scheduler.ts:23`, `core/src/hooks/dispatcher.ts:100`, `core/src/client/graphql.ts:71`\n\nSeveral `console.warn` calls are not gated behind `__DEV__` and will fire in production builds, potentially exposing internal framework state such as queue sizes, component names, and query fragments to users viewing the browser console.\n\n## Status\n\n**Open** — These warnings serve as development-time diagnostics. They do not expose credentials or PII, but may reveal internal architecture details.\n\n## Recommendation\n\nGate all development-time `console.warn` and `console.error` calls behind `process.env.NODE_ENV !== 'production'` or a `__DEV__` constant that build tools can tree-shake.","modified":"2026-09-10T03:51:11.798776372Z","published":"2026-07-02T19:03:10Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-209"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T19:03:10Z"},"references":[{"type":"WEB","url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-qcr8-x557-7cp3"},{"type":"WEB","url":"https://github.com/asymmetric-effort/specifyjs/commit/2ef791bc73ead853efd0c227ad8228bc594a7b63"},{"type":"PACKAGE","url":"https://github.com/asymmetric-effort/specifyjs"}],"affected":[{"package":{"name":"@asymmetric-effort/specifyjs","ecosystem":"npm","purl":"pkg:npm/%40asymmetric-effort/specifyjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.140"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.2.137","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qcr8-x557-7cp3/GHSA-qcr8-x557-7cp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}