highVulnerability

GHSA-w3hv-x4fp-6h6j

### Impact The WebSocket upgrade handler in the server validates authentication (API key token or session cookie) but does not check the `Origin` header. A malicious webpage on a different origin could initiate a WebSocket connection to `ws://localhost:3000/ws` if it can leverage the user's session cookie (which is `SameSite=Lax`, allowing top-level navigations). This enables **cross-origin WebSocket hijacking** — if a user visits a malicious site while a Grackle session is active, the attacker's page could open a WebSocket and subscribe to real-time events (session output, task updates, environment state). **Affected code:** - `packages/server/src/ws-bridge.ts:80-91` — connection handler accepts WebSocket upgrades without checking `req.headers.origin` ### Patches **Fix:** Validate `req.headers.origin` against an allowlist before accepting connections: ```typescript const origin = req.headers.origin || ""; if (origin && !origin.includes("localhost") && !origin.includes("127.0.0.1")) { ws.close(4003, "Invalid origin"); return; } ``` ### Workarounds Ensure the Grackle server is only accessible on `127.0.0.1` (the default). Do not use `--allow-network` in untrusted network environments. ### Resources - CWE-346: Origin Validation Error - File: `packages/server/src/ws-bridge.ts`

Properties

ghsa_id
GHSA-w3hv-x4fp-6h6j
severity
high
summary
@grackle-ai/server has Missing WebSocket Origin Header Validation
cve_id
GHSA-w3hv-x4fp-6h6j
is_ghsa_only
true
ghsa_published
2026-03-25T17:27:48Z
source_url
https://github.com/advisories/GHSA-w3hv-x4fp-6h6j
ghsa_updated
2026-03-25T17:28:07Z

Related Entities (3)

AFFECTS (1)

[Software]npm/@grackle-ai/server

HAS_WEAKNESS (1)

[Weakness]Origin Validation Error

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph