Every finding tells the full story.
Summary, affected code, a recorded proof of concept, and a fix checklist in one view. Validate it, comment on it, or hand it straight to a fix review.
- Impact context on every issue
- PoC code with highlighted lines and terminal replay
- Fix-ready recommendations
Spoofed Control UI locality silently mints persistent admin device tokens
Summary
Same-LAN or shared-token caller can spoof Control UI locality, silently pair an admin device, and retain admin authority after shared-token rotation.
Proof of concept
Copy1const config = {
2 gateway: {
3 bind: "lan",
4 auth: { mode: "token", token },
5 controlUi: {
6 enabled: true,
7 allowedOrigins: [`http://localhost:${port}`],
8 },
9 },
10};
Recommendation
Verify the immediate peer before trusting proxy headers; derive scopes from stored paired device records.



