Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The template loads executable JavaScript and CSS from third-party CDNs and also fetches map tiles from multiple remote providers at runtime. Even with SRI on Leaflet assets, this creates a supply-chain and privacy exposure: opening the generated HTML causes network requests, remote code execution in the browser context, and disclosure of user IP/usage metadata to external services.
