Highlights
Path Traversal: 1 prior fix. Scrutinize any change in this area.
pages/calendar.html: most-fixed (1 issue). Treat as high-risk during review.
2 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Path Traversal: The static file server joins user-supplied URL paths directly to the root directory, allowing traversal outside the serve root if not properly canonicalized.
Stored XSS: Calendar event data is inserted via .html(), enabling stored script execution if event content is attacker-controlled.