Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The code globally disables HTTPS certificate verification by replacing the default SSL context with an unverified one. This makes all HTTPS requests in the process vulnerable to man-in-the-middle interception or tampering, allowing an attacker on the network path to alter stock data or inject malicious responses despite the use of HTTPS.
