Severity: CRITICAL
Location: src/Controllers/AccountController.php:715-718
Bug: SELECT * from users, only password_hash is unset — totp_secret flows into the JSON download.
Fix: Whitelist columns or explicitly unset totp_secret, remember_token, and the sessions section.
Status: open. Will reply with remediation details when resolved.