There is an RCE vulnerability on the server component that allows anyone with access to the open port to execute arbitrary commands on the system. Fixed in my fork with version 2.3.1. Can provide pull request if needed. https://github.com/AngelouDi/predict