pinchtab
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecurityreferences/api.md
MEDIUMSecurityMEDIUM
references/api.md
This fragment documents a highly privileged browser-automation API. It contains no direct evidence of malware, but deployment security is critical: unauthenticated or weakly authorized access could permit session-cookie exposure, network credential leakage, arbitrary JavaScript execution, SSRF, local file reads or writes, uploads, and automated challenge bypass. The fragment alone cannot establish that these vulnerabilities exist in the implementation.
Confidence: 97%Severity: 72%
Audit Metadata