Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The copy pipeline automatically fetches image URLs and converts them to data URLs, causing the browser to make network requests to arbitrary image sources present in article content. This can leak user IP/addressing metadata, trigger unexpected requests to attacker-controlled hosts, and copy untrusted remote content into the exported article without clear user awareness.
