GHSA-5j35-xr4g-vwf4
@grackle-ai/server has a Missing Secure Flag on Session Cookie
Quick fix
GHSA-5j35-xr4g-vwf4 — @grackle-ai/server: upgrade to the fixed version with the command below.
npm install @grackle-ai/server@0.70.5Details
### Impact
The session cookie is set with `HttpOnly; SameSite=Lax; Path=/` but does not include the `Secure` flag. This means the cookie will be sent over plain HTTP connections.
Since the server binds to `127.0.0.1` by default and uses HTTP (not HTTPS), this is acceptable for localhost use. However, when `--allow-network` is used to bind to `0.0.0.0`, cookies could be transmitted over insecure network connections and intercepted by an attacker.
**Affected code:** - `packages/server/src/session.ts:76` — cookie string lacks `; Secure` attribute
### Patches
0.70.5
**Fix:** Conditionally add `; Secure` when served over HTTPS or when `--allow-network` is enabled: ```typescript const securePart = isHttps ? "; Secure" : ""; return `${SESSION_COOKIE_NAME}=${cookieValue}; HttpOnly; SameSite=Lax; Path=/${securePart}; Max-Age=${maxAge}`; ```
### Workarounds
Do not use `--allow-network` over untrusted networks without a TLS-terminating reverse proxy.
### Resources
- OWASP: Secure Cookie Attribute - File: `packages/server/src/session.ts`
Are you affected?
Enter the version of the package you're using.