Badges generated for private repos are publically visible

If you can guess the name of a repo you can fetch the badge with its build status by simply constructing the url http://drone/api/badges/user/project/status.svg.