Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script invokes wkhtmltopdf with --enable-local-file-access, which allows Markdown/HTML content being rendered to load arbitrary local files accessible to the current user. If the input Markdown is untrusted, an attacker can embed references to local files and potentially exfiltrate sensitive data into the generated PDF or otherwise access unintended local resources during rendering.
