{"id":"GHSA-xq7h-vwjp-5vrh","summary":"@grackle-ai/powerline Runs Without Authentication by Default","details":"### Impact\n\nWhen `--token` is not provided and `GRACKLE_POWERLINE_TOKEN` is not set, the PowerLine gRPC server runs with **zero authentication**. A warning is logged (`\"NO AUTH (development only)\"`) but nothing prevents deployment in this state. Any client that can reach the PowerLine port can spawn agent sessions, access credential tokens, and execute code.\n\nThe default binding is `127.0.0.1` (loopback only), which limits exposure to the local machine. However, if PowerLine is accidentally exposed on a network (e.g., in a container or via port forwarding), the impact is critical.\n\n**Affected code:**\n- `packages/powerline/src/index.ts:46` — token defaults to empty string\n- `packages/powerline/src/index.ts:63-76` — auth interceptor is only added when token is truthy\n\n### Patches\n\n0.70.1\n\n**Fix:** Require an explicit `--no-auth` flag to run without authentication, rather than defaulting to no auth when the token is empty. Throw an error if starting without a token and without `--no-auth`.\n\n### Workarounds\n\nAlways provide `--token` or set `GRACKLE_POWERLINE_TOKEN` when starting PowerLine. The Grackle server does this automatically when managing PowerLine lifecycle.\n\n### Resources\n\n- CWE-306: Missing Authentication for Critical Function\n- File: `packages/powerline/src/index.ts`","modified":"2026-03-25T17:46:26.776834Z","published":"2026-03-25T17:30:46Z","database_specific":{"cwe_ids":["CWE-306"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-25T17:30:46Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nick-pape/grackle/security/advisories/GHSA-xq7h-vwjp-5vrh"},{"type":"PACKAGE","url":"https://github.com/nick-pape/grackle"}],"affected":[{"package":{"name":"@grackle-ai/powerline","ecosystem":"npm","purl":"pkg:npm/%40grackle-ai/powerline"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.70.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.70.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xq7h-vwjp-5vrh/GHSA-xq7h-vwjp-5vrh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}