Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The download helper explicitly disables TLS hostname and certificate verification before fetching a remote image URL. This enables man-in-the-middle interception or spoofing of the remote endpoint, allowing an attacker on the network path or controlling DNS/proxy infrastructure to replace the generated image payload or serve malicious content while the client trusts it.
