Skip to content

SEC: Access Token Misconfiguration — insecure cookie flags #188

Description

@vybe

Pentest Finding 3.3.5 — Low (CVSS 2.0)

Location: Frontend cookie handling at http://localhost/

Impact

The application mirrors the Local Storage authentication token into a cookie without Secure or HttpOnly flags:

  • Missing Secure — browser transmits the token in plaintext over HTTP, enabling MitM session hijack on public Wi-Fi
  • Missing HttpOnly — token accessible via document.cookie, expanding XSS attack surface

While the app logic uses Local Storage for API communication, browsers automatically attach cookies to outbound requests, creating a secondary extraction vector.

Remediation

  • Best: Stop mirroring the token into a cookie entirely (if only Local Storage + Bearer header is used)
  • If cookie must be retained: set Secure, HttpOnly, and SameSite attributes
  • Ensure token is only transmitted over HTTPS connections

References

Source: UnderDefense Web Pentest Report, March 2026

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

complexity-lowComplexity: low (board points 1-3)pentestFrom penetration testing reportpriority-p2ImportantsecuritySecurity vulnerabilityseverity-lowLow severity security findingtheme-securityTheme: Security

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions