There is probably a difference between who is at risk.
If all you do is store URLs and not upload images to your server, your site is probably safe, and there is any potential risk for your users who are browsing your site.
Essentially, you trust the reliability of browser makers. Everything may be fine, but if in some browser a window should appear with protection from one of your users, which is associated with incorrect analysis of images containing malicious code, then these are your users who ultimately pay for it (you can find GIFAR is interesting).
It all depends on whether you trust browser vendors to make secure software and whether you trust your users not to upload URLs to images that may contain exploits for specific browsers. What can be safe now, may not be safe, the next version will appear.
source share