503
Critical
86
High
107
Medium
8
Low
704
Total
critical
81
mcp/create-server.mjs::mountKnowtationMcp
critical
81
hub/gateway/mcp-hosted-server.mjs::createHostedMcpServer
critical
80
cli/index.mjs::main
critical
78
web/hub/hub.js::attachNoteDetailReadActions
critical
78
test/section-source-hosted-implementation-spec.test.mjs::assertHostedSectionSourceAbsent
critical
78
test/hub-note-outline-self-hosted-route.test.mjs::routeSource
critical
78
web/hub/hub.js::renderSectionSourceData
critical
76
test/auth-session.test.mjs::fileStore
critical
76
test/auth-session.test.mjs::asyncSigner
critical
76
test/auth-session.test.mjs::issueAccessToken
critical
76
hub/refresh-tokens.mjs::rotateRefreshToken
critical
76
test/auth-refresh-wiring.test.mjs::load
critical
76
test/auth-session.test.mjs::clearCookie
critical
76
test/auth-session.test.mjs::cookieOptions
critical
76
hub/refresh-tokens.mjs::pruneRefreshTokens
critical
76
hub/lib/refresh-token-core.mjs::revokeFamily
critical
76
hub/refresh-tokens.mjs::readRefreshTokens
critical
76
hub/gateway/refresh-token-store.mjs::writeToFile
critical
76
hub/lib/refresh-token-core.mjs::parseToken
critical
76
hub/lib/refresh-token-core.mjs::revokeAllForSub
critical
76
hub/lib/refresh-token-core.mjs::safeEqualHashes
critical
76
hub/refresh-tokens.mjs::filePathFor
critical
76
test/section-source-hosted-implementation-spec.test.mjs::hostedRuntimeSource
critical
76
hub/refresh-tokens.mjs::revokeRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::saveRefreshRecords
critical
76
hub/refresh-tokens.mjs::writeRefreshTokens
critical
76
hub/lib/refresh-token-core.mjs::cloneRecords
critical
76
test/section-source-hosted-implementation-spec.test.mjs::connectPair
critical
76
test/section-source-hosted-implementation-spec.test.mjs::restore
critical
76
test/auth-session.test.mjs::cookie
critical
76
test/section-source-policy.test.mjs::readRepoFile
critical
76
hub/gateway/refresh-token-store.mjs::revokeAllRefreshTokensForSub
critical
76
hub/gateway/refresh-token-store.mjs::revokeRefreshToken
critical
76
hub/auth-session.mjs::refreshCookieOptions
critical
76
test/section-source-hosted-implementation-spec.test.mjs::readRepoFile
critical
76
test/mcp-section-source.test.mjs::sectionSourceToolSource
critical
76
test/section-source-hosted-implementation-spec.test.mjs::installFetchMock
critical
76
hub/gateway/refresh-token-store.mjs::writeToBlob
critical
76
hub/lib/refresh-token-core.mjs::hashSecret
critical
76
hub/lib/refresh-token-core.mjs::issueToken
critical
76
test/mcp-section-source.test.mjs::parseToolResult
critical
76
hub/lib/refresh-token-core.mjs::pruneExpired
critical
76
hub/gateway/refresh-token-store.mjs::refreshFilePath
critical
76
hub/lib/refresh-token-core.mjs::rotateToken
critical
76
test/mcp-section-source.test.mjs::readRepoFile
critical
76
hub/lib/refresh-token-core.mjs::sanitizeMeta
critical
76
hub/gateway/refresh-token-store.mjs::rotateRefreshToken
critical
76
hub/lib/refresh-token-core.mjs::generateRefreshToken
critical
76
test/section-source-hosted-implementation-spec.test.mjs::makeCtx
critical
76
hub/refresh-tokens.mjs::revokeAllRefreshTokensForSub