143
Critical
86
High
94
Medium
8
Low
331
Total
critical
81
mcp/create-server.mjs::mountKnowtationMcp
critical
81
hub/gateway/mcp-hosted-server.mjs::createHostedMcpServer
critical
80
cli/index.mjs::main
critical
78
web/hub/hub.js::renderSectionSourceData
critical
78
test/hub-note-outline-self-hosted-route.test.mjs::routeSource
critical
78
web/hub/hub.js::attachNoteDetailReadActions
critical
78
test/section-source-hosted-implementation-spec.test.mjs::assertHostedSectionSourceAbsent
critical
76
hub/lib/refresh-token-core.mjs::parseToken
critical
76
hub/gateway/refresh-token-store.mjs::saveRefreshRecords
critical
76
hub/lib/refresh-token-core.mjs::pruneExpired
critical
76
hub/gateway/refresh-token-store.mjs::revokeAllRefreshTokensForSub
critical
76
hub/gateway/refresh-token-store.mjs::rotateRefreshToken
critical
76
hub/lib/refresh-token-core.mjs::cloneRecords
critical
76
hub/lib/refresh-token-core.mjs::issueToken
critical
76
hub/gateway/refresh-token-store.mjs::loadRefreshRecords
critical
76
hub/gateway/refresh-token-store.mjs::getBlobStore
critical
76
hub/gateway/refresh-token-store.mjs::normalizeRecords
critical
76
hub/auth-session.mjs::readPresentedToken
critical
76
hub/auth-session.mjs::refreshHandler
critical
76
hub/gateway/refresh-token-store.mjs::createGatewayRefreshStore
critical
76
hub/gateway/refresh-token-store.mjs::issueRefreshToken
critical
76
test/mcp-section-source.test.mjs::readRepoFile
critical
76
hub/gateway/refresh-token-store.mjs::readFromFile
critical
76
hub/gateway/refresh-token-store.mjs::refreshFilePath
critical
76
hub/server.mjs::issueSession
critical
76
hub/gateway/refresh-token-store.mjs::revokeRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::writeToBlob
critical
76
hub/gateway/refresh-token-store.mjs::writeToFile
critical
76
hub/lib/refresh-token-core.mjs::generateRefreshToken
critical
76
hub/lib/refresh-token-core.mjs::hashSecret
critical
76
hub/auth-session.mjs::issueRefreshCookie
critical
76
hub/auth-session.mjs::refreshCookieOptions
critical
76
test/section-source-hosted-implementation-spec.test.mjs::readRepoFile
critical
76
test/mcp-section-source.test.mjs::connectPair
critical
76
test/hub-integration-guides.test.mjs::onOpen
critical
76
hub/auth-session.mjs::createRefreshHandler
critical
76
hub/auth-session.mjs::logoutHandler
critical
76
test/section-source-hosted-implementation-spec.test.mjs::restore
critical
76
test/section-source-hosted-implementation-spec.test.mjs::connectPair
critical
76
test/mcp-section-source.test.mjs::sectionSourceToolSource
critical
76
hub/auth-session.mjs::clearCookieOptions
critical
76
test/mcp-section-source.test.mjs::parseToolResult
critical
76
test/section-source-hosted-implementation-spec.test.mjs::hostedRuntimeSource
critical
76
test/section-source-hosted-implementation-spec.test.mjs::installFetchMock
critical
76
hub/auth-session.mjs::refreshError
critical
76
test/section-source-policy.test.mjs::readRepoFile
critical
76
test/section-source-hosted-implementation-spec.test.mjs::makeCtx
critical
76
hub/gateway/refresh-token-store.mjs::readFromBlob
critical
76
hub/gateway/refresh-token-store.mjs::pruneRefreshTokens
critical
76
hub/lib/refresh-token-core.mjs::revokeFamily