Junglewise Threat Intelligence

engram HTTP server CORS wildcard + missing auth enables CSRF and prompt injection

Severity: medium · CVSS 4 · Published 2026-04-22

Vendors: npm.

Executive brief

engram is an AI coding assistant that maintains a local knowledge graph of code patterns, decisions, and mistakes. The tool runs a local HTTP server (on localhost:7337 by default) that lacked authentication by default and sent permissive CORS headers allowing any web page a developer visited to exfiltrate the entire knowledge graph and inject persistent malicious instructions that would be repeated to the AI assistant on every future coding session. This could lead to data theft and manipulation of AI recommendations.

Technical details

The vulnerability is a combination of three security failures in engram's HTTP server: (1) wildcard CORS headers (Access-Control-Allow-Origin: *) on all responses, (2) authentication that defaults to "off" (checkAuth fails open when no token is set), and (3) the body parser accepting JSON without Content-Type validation, allowing text/plain requests to bypass CORS preflight. An attacker via a malicious web page can issue cross-origin requests to the localhost server. GET /query and GET /stats endpoints leak the knowledge graph contents (code structure, function names, recorded decisions). POST /learn accepts payloads without authentication, persisting attacker-controlled "mistake" and "decision" nodes that are later surfaced as system reminders to the AI agent on every session start and file edit. The vulnerability requires browser-based CSRF but affects all users by default; co-located attackers (malicious npm packages, browser extensions, Electron webviews) bypass network-level mitigations entirely. Patched in version 2.0.2 with fail-closed authentication (auto-generated token in ~/.engram/http-server.token), removal of wildcard CORS, Content-Type enforcement, and Host/Origin validation.

Affected products

  • NickCirv engram >=1.0.0, <2.0.2

Timeline

  • 2026-04-17: disclosed: Reported via GitHub issue #7
  • 2026-04-18: advisory: Advisory published as GHSA-2r2p-4cgf-hv7h
  • 2026-04-22: patched: Patched in version 2.0.2

References

Related threats