Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The renderer injects a remote Mermaid ES module from jsDelivr into every generated HTML document when Mermaid is enabled. That introduces third-party code execution, network dependency, and privacy/supply-chain risk in what is otherwise presented as a local markdown rendering/export path; if the CDN content is unavailable, tampered with, or blocked, output behavior changes and untrusted code may run in the viewer's browser.
