The kit binds the scraper API to 127.0.0.1 because the engine has no built-in authentication.
Do not expose port 8080 to a network without an authenticating proxy in front of it.
To report a vulnerability, use GitHub's private security advisory form. Do not open a public issue for security problems.