Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The function accepts an arbitrary out_path and writes rendered image files there without constraining the destination to a safe workspace. If an untrusted caller can influence that path, the tool can overwrite or create files outside the intended directory, enabling data clobbering, persistence, or placement of files in sensitive locations available to the running user.
