Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The generated HTML unconditionally loads KaTeX JavaScript and CSS from a third-party CDN. Opening the exported file causes network access and execution of remotely hosted script in the browser, which creates supply-chain and privacy risks that exceed a local-only PDF/OCR/note workflow; additionally, any unescaped Markdown content would execute in the same DOM context as those scripts.
