Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The client allows `LUX3D_BASE_URL` or `--base-url` to fully override the API root with no allowlist or host validation. Because authenticated requests include the Lux3D API key and user payloads such as prompts and images, an attacker who can influence configuration can redirect traffic to an arbitrary server and exfiltrate credentials and sensitive content.
