Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The bootstrap downloads `control-plane.js` from a remote server and later executes it with Node, giving the remote endpoint code execution on the local machine during installation. There is no signature verification, pinning, checksum validation, or trust boundary enforcement, so compromise of the API server, DNS/TLS interception, or a malicious operator would directly become arbitrary code execution.
