GHSA-5j35-xr4g-vwf4
### Impact The session cookie is set with `HttpOnly; SameSite=Lax; Path=/` but does not include the `Secure` flag. This means the cookie will be sent over plain HTTP connections. Since the server binds to `127.0.0.1` by default and uses HTTP (not HTTPS), this is acceptable for localhost use. However, when `--allow-network` is used to bind to `0.0.0.0`, cookies could be transmitted over insecure network connections and intercepted by an attacker. **Affected code:** - `packages/server/src/session.ts:76` — cookie string lacks `; Secure` attribute ### Patches 0.70.5 **Fix:** Conditionally add `; Secure` when served over HTTPS or when `--allow-network` is enabled: ```typescript const securePart = isHttps ? "; Secure" : ""; return `${SESSION_COOKIE_NAME}=${cookieValue}; HttpOnly; SameSite=Lax; Path=/${securePart}; Max-Age=${maxAge}`; ``` ### Workarounds Do not use `--allow-network` over untrusted networks without a TLS-terminating reverse proxy. ### Resources - OWASP: Secure Cookie Attribute - File: `packages/server/src/session.ts`
Properties
- ghsa_id
- GHSA-5j35-xr4g-vwf4
- severity
- low
- summary
- @grackle-ai/server has a Missing Secure Flag on Session Cookie
- cve_id
- GHSA-5j35-xr4g-vwf4
- is_ghsa_only
- true
- ghsa_published
- 2026-03-25T17:32:39Z
- source_url
- https://github.com/advisories/GHSA-5j35-xr4g-vwf4
- ghsa_updated
- 2026-03-25T17:32:40Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph