The Kubo API is bound within the container, and has no authentication.
This API allows full control over the IPFS node.
Impact is limited since this isn’t internet exposed, but it is reachable within the same docker network, and could get published by Oracle operators unaware of the risk.