This is an issue that’s overblown, simply have a firewall that exposes used ports and you’re fine.
There’s also an option within the release tool distillery to limit it to the local network.
Not to mention even if an attacker found your unsecured setup, they’d also need to know your “cookie”/key to do anything. It’s no different than leaving SSH login with password enabled on any server.