Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The script accepts a user-supplied --host and then sends file paths and optionally a bearer secret to that host over plain HTTP. This breaks the documented trust boundary of a local-only PicGo GUI helper and enables SSRF-style behavior, local file path disclosure, and credential leakage to arbitrary endpoints if an agent or user passes an attacker-controlled host.
