Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The template loads Chart.js from a third-party CDN at runtime, which introduces external network dependency and a supply-chain trust risk. If the CDN response is tampered with, unavailable, or swapped for a malicious script, the page could execute attacker-controlled JavaScript in the context of a report containing personal self-assessment data.
