lowVulnerability

GHSA-5j35-xr4g-vwf4

### Impact The session cookie is set with `HttpOnly; SameSite=Lax; Path=/` but does not include the `Secure` flag. This means the cookie will be sent over plain HTTP connections. Since the server binds to `127.0.0.1` by default and uses HTTP (not HTTPS), this is acceptable for localhost use. However, when `--allow-network` is used to bind to `0.0.0.0`, cookies could be transmitted over insecure network connections and intercepted by an attacker. **Affected code:** - `packages/server/src/session.ts:76` — cookie string lacks `; Secure` attribute ### Patches 0.70.5 **Fix:** Conditionally add `; Secure` when served over HTTPS or when `--allow-network` is enabled: ```typescript const securePart = isHttps ? "; Secure" : ""; return `${SESSION_COOKIE_NAME}=${cookieValue}; HttpOnly; SameSite=Lax; Path=/${securePart}; Max-Age=${maxAge}`; ``` ### Workarounds Do not use `--allow-network` over untrusted networks without a TLS-terminating reverse proxy. ### Resources - OWASP: Secure Cookie Attribute - File: `packages/server/src/session.ts`

Properties

ghsa_id
GHSA-5j35-xr4g-vwf4
severity
low
summary
@grackle-ai/server has a Missing Secure Flag on Session Cookie
cve_id
GHSA-5j35-xr4g-vwf4
is_ghsa_only
true
ghsa_published
2026-03-25T17:32:39Z
source_url
https://github.com/advisories/GHSA-5j35-xr4g-vwf4
ghsa_updated
2026-03-25T17:32:40Z

Related Entities (3)

AFFECTS (1)

[Software]npm/@grackle-ai/server

HAS_WEAKNESS (1)

[Weakness]Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5j35-xr4g-vwf4 — Ninja Signal Threat Intelligence | Ninja Signal