Context-Inappropriate Capability
Low
- Confidence
- 93% confidence
- Finding
- The code reads authentication material from an environment variable and persists the Quark session cookie in plaintext under the user's home directory. If the local system, account, or dotfiles are exposed, an attacker could reuse the stored cookie to access the user's cloud drive without re-authenticating.
