Skip to content

goklab/guardvibe

v2.8.0 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
gemini-cli-extension hono mcp nextjs owasp prisma static-analysis security stripe supabase supply-chain typescript vercel vibe-coding

Affected surfaces

deps rce_ssrf

Summary

AI summary

Added EU AI Act compliance reporting and extended security rule set with four new CVE-based rules.

Full changelog

v2.8.0 — New CVE Rules, EU AI Act Compliance, Glama Coherence

New Security Rules (+4)

| Rule | Severity | Description |
|------|----------|-------------|
| VG921 | Critical | @anthropic-ai/sdk <0.81.0 sandbox escape (CVE-2026-34451) |
| VG922 | High | defu <6.1.5 prototype pollution (CVE-2026-35209) |
| VG1003 | High | Hono ErrorBoundary XSS — v4.11.7 öncesi unsanitized error rendering |
| VG1004 | Medium | React Server Action without rate limiting (CVE-2026-23864) |

EU AI Act Compliance (EUAIACT)

  • compliance_report tool now supports EUAIACT framework
  • 30 AI security rules mapped to EU AI Act articles (Art10, Art13, Art14, Art15)
  • Covers: data governance, transparency, human oversight, accuracy & cybersecurity

Glama Server Coherence

  • Added description to McpServer constructor (was missing)
  • Improved tool descriptions for policy_check, generate_policy, get_security_docs, scan_secrets

Numbers

334 rules, 29 tools, 23 CVEs

Security Fixes

  • VG921 — Critical: `@anthropic-ai/sdk` <0.81.0 sandbox escape (CVE-2026-34451)
  • VG922 — High: `defu` <6.1.5 prototype pollution (CVE-2026-35209)
  • VG1003 — High: Hono ErrorBoundary XSS before v4.11.7
  • VG1004 — Medium: React Server Action without rate limiting (CVE-2026-23864)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Beta — feedback welcome: [email protected]