Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The generated CRUD cloud function accepts action, collection, data, id, and where directly from the caller and performs unrestricted database operations with no authentication, authorization, or collection allowlisting. In a cloud-function context, deploying this template as-is can expose arbitrary reads, writes, updates, and deletes across backend data, making it a dangerous insecure-by-default scaffold.
