Tried researching exploits/vulns based on imgs with external sources. Not really finding anything that serious or that hasn't been fixed. Will look into more.
My test vector was spoofing the return header and sending back something that's not an image.