Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The renderer globally enables JavaScript in wkhtmltoimage even though this skill’s purpose is server-side image generation from HTML templates. Because the generated HTML includes user-controlled content such as image URLs and other template fields, enabling script execution expands the attack surface and can allow active content to run during rendering, including network requests or exploitation of the rendering engine if HTML injection is ever achieved elsewhere.
