Application security review

Severity, exploit path, exact fix. No patches until approved.

Pre-launch audit. OWASP-minded, still specific to the pasted code.

Public marketing description for a developer asset on CodeHub. Protected bodies are not exposed here when the asset is premium or private.