Same user followed up with a second severity HIGH security problem.
"The --capath option in cURL and CURLOPT_CAPATH in libcurl accept any directory path without validation. If an attacker provides a custom CA path containing a fake root certificate, cURL will trust malicious HTTPS endpoints signed with that fake root."
I'm fortunate to get to work with the best people 🤠