Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The documentation explicitly recommends adding 'unsafe-eval' to the extension_pages CSP to make React DevTools work. In a browser extension, weakening CSP this way increases the attack surface for script-injection-style abuse and normalizes an unsafe production configuration for a non-essential debugging convenience.
