Vulnerabilities/

@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection

Severity:
Medium

Description

Location: core/src/client/graphql.ts:66-80

The gql template tag function warned about interpolated values containing GraphQL metacharacters ({}():) but still concatenated them into the query string, enabling potential GraphQL injection.

Recommendation

Update the @asymmetric-effort/specifyjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@asymmetric-effort/specifyjs
Anything's wrong? Let us know Last updated on July 02, 2026