Admin authorization is npub-membership only — any admin can act on any key
NIP-46 transport matches responses by request id only — no binding to the peer the request was sent to
create_account persists the generated nsec as plaintext hex in the config file
create_account is reachable without the admin allowlist (allowNewKeys hardcoded true) and has no throttling
Connection tokens and NIP-46 request ids are generated with Math.random()
Inbound Nostr sync accepts calendar events from any pubkey: takeover of local events and unmoderated catalog injection
Refunds can double-pay, and the public GET /api/v1/events/{id} cancels and refunds as a side effect
Ticket oversell: capacity is never reserved between invoice creation and settlement
A failed payout permanently burns a unique sub-link: allowance is consumed before
pay_invoice and not restored on failure
Lightning-address usernames are not unique: transport create/update skip the check and the schema has no constraint
Nostr-transport create/update bypass the HTTP validation; fiat links created over the transport are served at 1/100 of the configured price
webhook_url is unvalidated: server-side POST with attacker-chosen headers to any host (SSRF)
Settlement loop has no per-payment error isolation; a malformed zap request drops webhooks and zaps for other paylinks
Gift-wrap redelivery on restart re-sends "Order already received" to every past customer and inflates unread counts
NostrRouter buffers are ClassVars: unbounded growth and isolation-by-luck between connections
invoice_paid_for_storage overwrites account.storage instead of adding to it
get_accounts WHERE clause is unscoped by relay for the blocked branch