Executive brief
A vulnerability in the specifyjs framework causes internal diagnostic information to be printed to the browser's console in production environments. This could allow an observer to see technical details about the application's internal architecture, such as component names and database query fragments. While it does not directly expose user passwords or personal data, it provides technical insights that could assist an attacker in planning more complex attacks.
Technical details
The vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). Several 'console.warn' and 'console.error' calls in the scheduler, dispatcher, and GraphQL client components were not gated by environment checks (e.g., NODE_ENV !== 'production'). Consequently, production builds leak internal state including queue sizes, component names, and GraphQL query fragments to the client-side console. An attacker can access this information by simply viewing the browser's developer tools. The issue is resolved in version 0.2.139 and later by implementing production-mode suppression for diagnostic logging.
Affected products
- asymmetric-effort specifyjs <= 0.2.137
Timeline
- 2026-05-29: disclosed: Initial disclosure by maintainers
- 2026-05-29: patched: Fixed in version 0.2.139
- 2026-07-02: advisory: GitHub Advisory published