Absolutely, but what would normally fall under "third-party" threats is the ability to identify (probabilistically enough) the person who triggered a load so as to track their behaviour. So the threat is the same for all IPFS loads you don't already have.
♥ 1