Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354959d915974a332445f1b3c223606cfd5502428ab8
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/About/Version
GET /v1/FileMetadata
GET /v1/FileMetadata({key})
GET /v1/FileMetadata/$count
GET /v1/FileMetadata/{key}
GET /v1/{organizationId}/FileMetadata
GET /v1/{organizationId}/FileMetadata/{key}
GET /v1/{organizationId}/Files/ApiUrl/{apiURL}
GET /v1/{organizationId}/Files/Url/{id}
GET /v1/{organizationId}/Files/Url/{path}
GET /v1/{organizationId}/Files/{id}
GET /v1/{organizationId}/Files/{path}
POST /v1/{organizationId}/Files
POST /v1/{organizationId}/Files/Copy
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354959d915974a332445f1b3c223606cfd5541d9478d
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/About/Version
GET /v1/FileMetadata
GET /v1/FileMetadata({key})
GET /v1/FileMetadata/$count
GET /v1/FileMetadata/{key}
GET /v1/{organizationId}/FileMetadata
GET /v1/{organizationId}/FileMetadata/{key}
GET /v1/{organizationId}/Files/Url/{id}
GET /v1/{organizationId}/Files/Url/{path}
GET /v1/{organizationId}/Files/{id}
GET /v1/{organizationId}/Files/{path}
POST /v1/{organizationId}/Files
POST /v1/{organizationId}/Files/Copy
Open service 20.105.224.45:443 · files.dev.workai.cloud
2026-01-23 15:59
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Fri, 23 Jan 2026 16:00:08 GMT Set-Cookie: ARRAffinity=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;Secure;Domain=files.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;SameSite=None;Secure;Domain=files.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: 9d9fdba609bd3a41e8de1aecc02a5c89 healthy
Open service 20.105.224.45:443 · files.dev.workai.cloud
2026-01-09 16:30
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Fri, 09 Jan 2026 16:31:41 GMT Set-Cookie: ARRAffinity=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;Secure;Domain=files.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;SameSite=None;Secure;Domain=files.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: a0ff70b17d63adbac7ca79395c5d8ceb healthy
Open service 20.105.224.45:443 · files.dev.workai.cloud
2026-01-02 21:33
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Fri, 02 Jan 2026 21:33:11 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=files.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=files.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: 0db0687d0b2d711845756d019fdfb8e9 healthy
Open service 20.105.224.45:80 · files.dev.workai.cloud
2025-12-24 00:14
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Wed, 24 Dec 2025 00:14:00 GMT Location: https://files.dev.workai.cloud/
Open service 20.105.224.45:443 · files.dev.workai.cloud
2025-12-24 00:14
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Wed, 24 Dec 2025 00:14:01 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=files.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=files.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: fdb2fdbd19b91548c651acf75cb3fff5 healthy
Open service 20.105.224.45:443 · files.dev.workai.cloud
2025-12-22 22:56
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Mon, 22 Dec 2025 22:56:36 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=files.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=files.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: c3d469300541f4b4c1f3719fa9223a0d healthy