Executive brief
@asymmetric-effort/specifyjs is a JavaScript framework used for building component-based applications. Development debugging console warnings intended for developers are being output in production builds, potentially revealing internal architecture details such as queue sizes and component names to end users viewing the browser console. While this does not expose credentials or personal information, it provides attackers reconnaissance information about the application's internal structure.
Technical details
This vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The root cause is that multiple console.warn() and console.error() calls in core/src/core/scheduler.ts, core/src/hooks/dispatcher.ts, and core/src/shared/warnings.ts are not gated behind a NODE_ENV or __DEV__ check, causing them to execute in production builds. The attack vector is network-based and requires no authentication—an attacker simply views the browser developer console to observe queue sizes, component names, and query fragments. The fix, available in version 0.2.139, gates all development-time console output behind NODE_ENV !== 'production' checks while preserving the actual queue trimming behavior.
Affected products
- asymmetric-effort @asymmetric-effort/specifyjs < 0.2.139
Timeline
- 2026-05-29: disclosed
- 2026-05-29: patched: Fixed in v0.2.139