Junglewise Threat Intelligence

@asymmetric-effort/specifyjs information disclosure via console warnings

Severity: medium · CVSS 4 · Published 2026-07-02

Technologies: @asymmetric-effort/specifyjs (npm), Asymmetric Effort Specifyjs. Vendors: npm, Asymmetric Effort.

Executive brief

@asymmetric-effort/specifyjs is a JavaScript framework used for building component-based applications. Development debugging console warnings intended for developers are being output in production builds, potentially revealing internal architecture details such as queue sizes and component names to end users viewing the browser console. While this does not expose credentials or personal information, it provides attackers reconnaissance information about the application's internal structure.

Technical details

This vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The root cause is that multiple console.warn() and console.error() calls in core/src/core/scheduler.ts, core/src/hooks/dispatcher.ts, and core/src/shared/warnings.ts are not gated behind a NODE_ENV or __DEV__ check, causing them to execute in production builds. The attack vector is network-based and requires no authentication—an attacker simply views the browser developer console to observe queue sizes, component names, and query fragments. The fix, available in version 0.2.139, gates all development-time console output behind NODE_ENV !== 'production' checks while preserving the actual queue trimming behavior.

Affected products

  • asymmetric-effort @asymmetric-effort/specifyjs < 0.2.139

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: patched: Fixed in v0.2.139

References

Related threats