Yes.
Any normal attacks that could be executed against a server on the internet could now be executed against your local server.
Which means, if your local/dev API endpoints have vulnerabilities, you will be exposed.
To help protect against attacks, you will want to block all 3rd party requests.
A possible solution would be to use HTTP basic auth (assuming tunnelto passes along the basic auth headers).
Ex. https://user:pass@t1.tunnelto.dev/api/hello
Then on your local/dev server, check user & pass.