Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The setup instructs users to bind SearXNG to 0.0.0.0, which exposes the service on all network interfaces rather than localhost only. In the context of a self-hosted search service with a JSON API and no accompanying warning about authentication, firewalling, or reverse-proxy protection, this can unintentionally make the instance reachable by other hosts on the LAN or internet and enable unauthorized use, scraping, or abuse.
