Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- On successful login, the page displays the returned authentication token directly in the UI and later persists it in browser storage. Exposing bearer credentials to the page and to anyone with local browser access, extensions, or injected script greatly increases the chance of account compromise, and this behavior is broader than a normal QR-login UX requires.
