Description-Behavior Mismatch
Medium
- Confidence
- 99% confidence
- Finding
- The server binds to 0.0.0.0, making an interface described as 'local memory search' reachable from other hosts on the network, not just the local machine. Because it serves MEMORY.md, WORKING.md, and memory logs with no authentication, any reachable client could query and exfiltrate sensitive agent history, secrets, or operational context.
