{"id":"GHSA-3mjm-x6gw-2x42","summary":"@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers","details":"### Impact\n\nThe HTTP server does not set `Content-Security-Policy`, `X-Frame-Options`, or `X-Content-Type-Options` headers on any response. This reduces defense-in-depth against XSS, clickjacking, and MIME-sniffing attacks.\n\nWhile the current XSS attack surface is small (React-markdown is configured safely, no `dangerouslySetInnerHTML`, Vite does not generate source maps), the absence of these headers means any future XSS vulnerability would have no secondary defense layer.\n\n**Affected code:**\n- `packages/server/src/index.ts` — all `res.writeHead()` calls only set `Content-Type`, with no security headers\n\n### Patches\n\n0.70.4\n\n**Fix:** Add security headers to all HTML/API responses:\n```typescript\nres.writeHead(200, {\n  \"Content-Type\": contentType,\n  \"Content-Security-Policy\": \"default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:\",\n  \"X-Frame-Options\": \"DENY\",\n  \"X-Content-Type-Options\": \"nosniff\"\n});\n```\n\n### Workarounds\n\nUse a reverse proxy (nginx, Caddy) in front of the Grackle server to inject security headers.\n\n### References\n\n- CWE-693: Protection Mechanism Failure\n- OWASP: HTTP Security Response Headers\n- File: `packages/server/src/index.ts`","modified":"2026-03-25T17:46:27.723451Z","published":"2026-03-25T17:32:04Z","database_specific":{"cwe_ids":["CWE-693","CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-25T17:32:04Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nick-pape/grackle/security/advisories/GHSA-3mjm-x6gw-2x42"},{"type":"PACKAGE","url":"https://github.com/nick-pape/grackle"}],"affected":[{"package":{"name":"@grackle-ai/server","ecosystem":"npm","purl":"pkg:npm/%40grackle-ai/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.70.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3mjm-x6gw-2x42/GHSA-3mjm-x6gw-2x42.json","last_known_affected_version_range":"\u003c= 0.70.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}