Good point, but syncthing only listens on localhost as others have said too.
However it still is a network service that can have vulnerabilities, besides many others like KDE Connect (which may be a target as one of its purposes is remote control and monitoring) or a bittorrent client
deleted by creator
Is syncthing listening on all addresses, or only loopback? A firewall would block it, sure, but that would also be bad design.
Syncthing only listens on loopback by default unless you modify the config.
Good point, but syncthing only listens on localhost as others have said too.
However it still is a network service that can have vulnerabilities, besides many others like KDE Connect (which may be a target as one of its purposes is remote control and monitoring) or a bittorrent client