Eh, it's since been backed down from a red alert to "code brown on isle 9."  Originally it was though there was a vulnerability that permitted exicution of SQF code on a client machine from a compromised/malicious server.  They've since verified that it only gives the ability to read file contents if specific things are done first.