security-pass.txt
Review this for security holes: <paste>

Check specifically for:
- User input reaching a database query or a shell command unescaped.
- User input reaching the page unescaped.
- Any route that changes data without checking who is asking.
- Any route that returns someone else's data if I change an ID in the URL.
- Secrets in the source, and errors that leak internals to the user.

For each finding: the line, what an attacker does with it, the fix.
Rank by how easy it would be to exploit with no special access.

Changing an ID in a URL and getting someone else's record is the most common real-world flaw in vibe-coded apps. Check that one first, every time.