GHSA-7q9x-8g6p-3x75

Suggest an improvement
Source
https://github.com/advisories/GHSA-7q9x-8g6p-3x75
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7q9x-8g6p-3x75/GHSA-7q9x-8g6p-3x75.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7q9x-8g6p-3x75
Published
2026-03-25T17:15:40Z
Modified
2026-03-25T17:32:20Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Details

Impact

The renderPairingPage() function embeds the error parameter directly into HTML without escaping:

const errorHtml = error ? `<p style="color:#e74c3c">${error}</p>` : "";

All current call sites pass hardcoded strings, so this is not exploitable today. However, the function is architecturally fragile — if a future code change passes user-controlled or dynamic content into the error parameter, it would create an XSS vulnerability.

The renderAuthorizePage() function in the same file correctly uses escapeHtml() for dynamic content, making this an inconsistency.

Affected code:

  • packages/server/src/index.ts:64-89 — renderPairingPage() with unescaped error interpolation
  • Compare: packages/server/src/index.ts:130 — renderAuthorizePage() correctly uses escapeHtml()

Patches

v0.70.1

Fix: Apply escapeHtml() to the error parameter:

const errorHtml = error ? `<p style="color:#e74c3c">${escapeHtml(error)}</p>` : "";

Workarounds

No workaround needed — all current callers pass hardcoded strings.

Resources

  • CWE-79: Improper Neutralization of Input During Web Page Generation
  • File: packages/server/src/index.ts
Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-25T17:15:40Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / @grackle-ai/server

Package

Name
@grackle-ai/server
View open source insights on deps.dev
Purl
pkg:npm/%40grackle-ai/server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.70.1

Database specific

last_known_affected_version_range
"<= 0.70.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7q9x-8g6p-3x75/GHSA-7q9x-8g6p-3x75.json"