This is exactly why services that expose unnecessary network services drive me batty.
The extent of this vulnerability would have been significantly limited if it were only enabled for users using the feature (e.g., not Android Studio, PyCharm, or other users) and even more-so if it were enabled on-demand.
In recent memory, both CodeKit and Prepros really want to have some live preview HTTP server enabled all the time. Simply enabling it when the user hit the "Open Live Preview" button in the app would significantly reduce the attack surface. As would giving users the option to enable/disable it at will.