Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The API enables cross-origin access from any website via Access-Control-Allow-Origin: * and exposes read/write/delete operations without any visible authentication or origin restriction. This makes the generated backend broadly callable by arbitrary web pages, increasing the risk of unauthorized data access or destructive actions if deployed as-is.
