{"id":"GHSA-xq7h-vwjp-5vrh","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xq7h-vwjp-5vrh","summary":"@grackle-ai/powerline Runs Without Authentication by Default","details":"### Impact\n\nWhen `--token` is not provided and `GRACKLE_POWERLINE_TOKEN` is not set, the PowerLine gRPC server runs with **zero authentication**. A warning is logged (`\"NO AUTH (development only)\"`) but nothing prevents deployment in this state. Any client that can reach the PowerLine port can spawn agent sessions, access credential tokens, and execute code.\n\nThe default binding is `127.0.0.1` (loopback only), which limits exposure to the local machine. However, if PowerLine is accidentally exposed on a network (e.g., in a container or via port forwarding), the impact is critical.\n\n**Affected code:**\n- `packages/powerline/src/index.ts:46` — token defaults to empty string\n- `packages/powerline/src/index.ts:63-76` — auth interceptor is only added when token is truthy\n\n### Patches\n\n0.70.1\n\n**Fix:** Require an explicit `--no-auth` flag to run without authentication, rather than defaulting to no auth when the token is empty. Throw an error if starting without a token and without `--no-auth`.\n\n### Workarounds\n\nAlways provide `--token` or set `GRACKLE_POWERLINE_TOKEN` when starting PowerLine. The Grackle server does this automatically when managing PowerLine lifecycle.\n\n### Resources\n\n- CWE-306: Missing Authentication for Critical Function\n- File: `packages/powerline/src/index.ts`","published":"2026-03-25T17:30:46Z","modified":"2026-03-25T17:46:26.776834Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@grackle-ai/powerline","fixedVersion":"0.70.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/nick-pape/grackle/security/advisories/GHSA-xq7h-vwjp-5vrh"},{"type":"PACKAGE","url":"https://github.com/nick-pape/grackle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-25T17:46:26.776834Z"}}