Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The documentation exposes an in-process HTTP testing interface with powerful capabilities including widget-tree enumeration, screenshots, synthetic input, and chaos/fuzz actions. If this interface is enabled in non-test contexts or lacks strict localhost-only binding, authentication, and build gating, it creates a local or potentially remote control surface for the application that can leak sensitive UI data and drive privileged actions.
