Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The server enables CORS for all origins and exposes unauthenticated mutation endpoints such as add, convert, delete, enrich, and save. Because it binds to 0.0.0.0, any reachable host or any website visited by the user can send cross-origin requests that modify or delete the local graph file, which is a real integrity issue rather than a mere design concern.
