Description

### Impact The session cookie is set with `HttpOnly; SameSite=Lax; Path=/` but does not include the `Secure` flag. This means the cookie will be sent over plain HTTP connections. Since the server binds to `127.0.0.1` by default and uses HTTP (not HTTPS), this is acceptable for localhost use. However, when `--allow-network` is used to bind to `0.0.0.0`, cookies could be transmitted over insecure network connections and intercepted by an attacker. **Affected code:** - `packages/server/src/session.ts:76` — cookie string lacks `; Secure` attribute ### Patches 0.70.5 **Fix:** Conditionally add `; Secure` when served over HTTPS or when `--allow-network` is enabled: ```typescript const securePart = isHttps ? "; Secure" : ""; return `${SESSION_COOKIE_NAME}=${cookieValue}; HttpOnly; SameSite=Lax; Path=/${securePart}; Max-Age=${maxAge}`; ``` ### Workarounds Do not use `--allow-network` over untrusted networks without a TLS-terminating reverse proxy. ### Resources - OWASP: Secure Cookie Attribute - File: `packages/server/src/session.ts`

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 0.70.5 · Fixed in 0.70.5affected

References

2