As I said, I an not a dev, just someone that uses the app and wanted to see if AI could find anything. The BLUF is that the code security is good, there are just some minor coding tweaks that could be done. But I don't know near enough to say if they are needed. Thanks for working on this, I really like the app!
After seeing lots of people stepping up and looking at code over the weekend after the Coldcard hack I decided to look at the KeePass code. I am not a programer, but I use the app. Here is what I found. Findings at a Glance ID Finding Severity Class F-01 Path traversal in PLGX file extraction High CWE-22 F-02 Command execution from PLGX-supplied build fields High CWE-78 / design F-03 Unbounded pre-authentication allocation from KDBX header Medium CWE-789 F-04 No upper bound on attacker-supplied KDF...