143
Critical
86
High
94
Medium
8
Low
331
Total
critical
81
mcp/create-server.mjs::mountKnowtationMcp
critical
81
hub/gateway/mcp-hosted-server.mjs::createHostedMcpServer
critical
80
cli/index.mjs::main
critical
78
test/hub-note-outline-self-hosted-route.test.mjs::routeSource
critical
78
web/hub/hub.js::renderSectionSourceData
critical
78
test/section-source-hosted-implementation-spec.test.mjs::assertHostedSectionSourceAbsent
critical
78
web/hub/hub.js::attachNoteDetailReadActions
critical
76
web/hub/hub.js::api
critical
76
test/gateway-refresh-token-store.test.mjs::setJSON
critical
76
web/hub/hub-integration-guides.mjs::wireIntegrationTiles
critical
76
hub/auth-session.mjs::createLogoutHandler
critical
76
test/gateway-refresh-token-store.test.mjs::get
critical
76
test/refresh-tokens-store.test.mjs::storeFile
critical
76
web/hub/hub.js::refreshAccessToken
critical
76
hub/server.mjs::issueAccessTokenForSub
critical
76
test/gateway-session-introspection.test.mjs::validPayload
critical
76
hub/server.mjs::refreshCookiePolicy
critical
76
test/gateway-auth-refresh-wiring.test.mjs::load
critical
76
hub/refresh-tokens.mjs::revokeAllRefreshTokensForSub
critical
76
test/gateway-session-introspection.test.mjs::startServer
critical
76
test/refresh-token-core.test.mjs::buildLargeStore
critical
76
hub/gateway/server.mjs::scopesForRole
critical
76
test/auth-session.test.mjs::clearCookie
critical
76
netlify/functions/gateway.mjs::handler
critical
76
hub/refresh-tokens.mjs::filePathFor
critical
76
test/gateway-refresh-token-store.test.mjs::createStubBlobStore
critical
76
test/auth-session.test.mjs::asyncSigner
critical
76
test/gateway-session-introspection.test.mjs::createGateway
critical
76
hub/gateway/server.mjs::decodeVerifiedToken
critical
76
hub/gateway/server.mjs::refreshCookiePolicy
critical
76
test/auth-session.test.mjs::mockRes
critical
76
test/gateway-session-introspection.test.mjs::get
critical
76
test/auth-session.test.mjs::fileStore
critical
76
test/auth-session.test.mjs::cookieOptions
critical
76
hub/lib/refresh-token-core.mjs::sanitizeMeta
critical
76
hub/refresh-tokens.mjs::revokeRefreshToken
critical
76
test/auth-session.test.mjs::set
critical
76
test/auth-session.test.mjs::status
critical
76
hub/gateway/refresh-token-store.mjs::readFromBlob
critical
76
hub/lib/refresh-token-core.mjs::pruneExpired
critical
76
hub/gateway/refresh-token-store.mjs::pruneRefreshTokens
critical
76
hub/gateway/refresh-token-store.mjs::normalizeRecords
critical
76
hub/refresh-tokens.mjs::readRefreshTokens
critical
76
hub/server.mjs::issueSession
critical
76
hub/lib/refresh-token-core.mjs::issueToken
critical
76
hub/gateway/refresh-token-store.mjs::writeToBlob
critical
76
hub/refresh-tokens.mjs::writeRefreshTokens
critical
76
test/auth-refresh-wiring.test.mjs::load
critical
76
hub/refresh-tokens.mjs::rotateRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::writeToFile
critical
76
test/section-source-hosted-implementation-spec.test.mjs::restore
critical
76
hub/lib/refresh-token-core.mjs::revokeAllForSub
critical
76
test/mcp-section-source.test.mjs::connectPair
critical
76
test/section-source-policy.test.mjs::readRepoFile
critical
76
test/auth-session.test.mjs::issueAccessToken
critical
76
hub/lib/refresh-token-core.mjs::cloneRecords
critical
76
hub/lib/refresh-token-core.mjs::safeEqualHashes
critical
76
test/gateway-session-introspection.test.mjs::adminPayload
critical
76
hub/auth-session.mjs::clearCookieOptions
critical
76
hub/lib/refresh-token-core.mjs::generateRefreshToken
critical
76
hub/gateway/server.mjs::issueAccessTokenForSub
critical
76
hub/gateway/server.mjs::issueRefreshCookieSafe
critical
76
test/auth-session.test.mjs::cookie
critical
76
test/auth-session.test.mjs::json
critical
76
test/gateway-session-introspection.test.mjs::makeJwt
critical
76
hub/server.mjs::handleAuthCallback
critical
76
hub/auth-session.mjs::createRefreshHandler
critical
76
hub/lib/refresh-token-core.mjs::revokeFamily
critical
76
hub/auth-session.mjs::issueRefreshCookie
critical
76
hub/auth-session.mjs::refreshHandler
critical
76
test/hub-integration-guides.test.mjs::onOpen
critical
76
test/section-source-hosted-implementation-spec.test.mjs::installFetchMock
critical
76
hub/auth-session.mjs::refreshError
critical
76
hub/refresh-tokens.mjs::issueRefreshToken
critical
76
hub/auth-session.mjs::logoutHandler
critical
76
hub/refresh-tokens.mjs::pruneRefreshTokens
critical
76
hub/auth-session.mjs::readPresentedToken
critical
76
hub/auth-session.mjs::refreshCookieOptions
critical
76
hub/gateway/refresh-token-store.mjs::createGatewayRefreshStore
critical
76
test/mcp-section-source.test.mjs::sectionSourceToolSource
critical
76
hub/gateway/refresh-token-store.mjs::getBlobStore
critical
76
test/section-source-hosted-implementation-spec.test.mjs::hostedRuntimeSource
critical
76
hub/gateway/refresh-token-store.mjs::issueRefreshToken
critical
76
test/mcp-section-source.test.mjs::readRepoFile
critical
76
test/mcp-section-source.test.mjs::parseToolResult
critical
76
hub/gateway/refresh-token-store.mjs::loadRefreshRecords
critical
76
hub/gateway/refresh-token-store.mjs::readFromFile
critical
76
hub/lib/refresh-token-core.mjs::parseToken
critical
76
hub/gateway/refresh-token-store.mjs::revokeAllRefreshTokensForSub
critical
76
hub/gateway/refresh-token-store.mjs::refreshFilePath
critical
76
hub/gateway/refresh-token-store.mjs::revokeRefreshToken
critical
76
test/section-source-hosted-implementation-spec.test.mjs::connectPair
critical
76
hub/gateway/refresh-token-store.mjs::rotateRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::saveRefreshRecords
critical
76
hub/lib/refresh-token-core.mjs::hashSecret
critical
76
hub/lib/refresh-token-core.mjs::rotateToken
critical
76
hub/lib/refresh-token-core.mjs::revokeToken
critical
76
test/section-source-hosted-implementation-spec.test.mjs::readRepoFile
critical
76
test/section-source-hosted-implementation-spec.test.mjs::makeCtx
critical
76
web/hub/hub-integration-guides.mjs::listIntegrationGuideIds