VDB
Sign up
LOW

GHSA-5j35-xr4g-vwf4

@grackle-ai/server has a Missing Secure Flag on Session Cookie

Quick fix

GHSA-5j35-xr4g-vwf4 — @grackle-ai/server: upgrade to the fixed version with the command below.

npm install @grackle-ai/server@0.70.5

Details

### Impact

The session cookie is set with `HttpOnly; SameSite=Lax; Path=/` but does not include the `Secure` flag. This means the cookie will be sent over plain HTTP connections.

Since the server binds to `127.0.0.1` by default and uses HTTP (not HTTPS), this is acceptable for localhost use. However, when `--allow-network` is used to bind to `0.0.0.0`, cookies could be transmitted over insecure network connections and intercepted by an attacker.

**Affected code:** - `packages/server/src/session.ts:76` — cookie string lacks `; Secure` attribute

### Patches

0.70.5

**Fix:** Conditionally add `; Secure` when served over HTTPS or when `--allow-network` is enabled: ```typescript const securePart = isHttps ? "; Secure" : ""; return `${SESSION_COOKIE_NAME}=${cookieValue}; HttpOnly; SameSite=Lax; Path=/${securePart}; Max-Age=${maxAge}`; ```

### Workarounds

Do not use `--allow-network` over untrusted networks without a TLS-terminating reverse proxy.

### Resources

- OWASP: Secure Cookie Attribute - File: `packages/server/src/session.ts`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@grackle-ai/server
Introduced in: 0Fixed in: 0.70.5
Fixnpm install @grackle-ai/server@0.70.5

References