Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The /api/status endpoint exposes aggregated metadata from all discovered projects over HTTP, and the server sets Access-Control-Allow-Origin: * for all responses. Although the listener is restricted to 127.0.0.1, any website visited by the user could potentially read localhost responses from a browser, turning local verification/project metadata into cross-origin accessible data.
