Earlier quoted context omitted.
Finding a years abandoned Linux server on your home network m ight be a good leasson to always treat your home network as if it was compromised.
Honestly curious: how would you exploit it? If the pi isn't exposed to the www by your router, what can you do?
Essentially - it's reading user-defined data - which is probably enough to be really bad, incase of a malicious exploit in the wild.