Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The tool invokes a shell command via execSync using attacker-controlled input derived from the URL parameter. Even though the feature is framed as scraping, exposing subprocess execution creates a command-injection path if the URL contains shell metacharacters or quoting tricks, allowing arbitrary local command execution under the server's privileges.
