This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryAdded EU AI Act compliance reporting and extended security rule set with four new CVE-based rules.
Full changelog
v2.8.0 — New CVE Rules, EU AI Act Compliance, Glama Coherence
New Security Rules (+4)
| Rule | Severity | Description |
|------|----------|-------------|
| VG921 | Critical | @anthropic-ai/sdk <0.81.0 sandbox escape (CVE-2026-34451) |
| VG922 | High | defu <6.1.5 prototype pollution (CVE-2026-35209) |
| VG1003 | High | Hono ErrorBoundary XSS — v4.11.7 öncesi unsanitized error rendering |
| VG1004 | Medium | React Server Action without rate limiting (CVE-2026-23864) |
EU AI Act Compliance (EUAIACT)
compliance_reporttool now supportsEUAIACTframework- 30 AI security rules mapped to EU AI Act articles (Art10, Art13, Art14, Art15)
- Covers: data governance, transparency, human oversight, accuracy & cybersecurity
Glama Server Coherence
- Added
descriptionto McpServer constructor (was missing) - Improved tool descriptions for
policy_check,generate_policy,get_security_docs,scan_secrets
Numbers
334 rules, 29 tools, 23 CVEs
Security Fixes
- VG921 — Critical: `@anthropic-ai/sdk` <0.81.0 sandbox escape (CVE-2026-34451)
- VG922 — High: `defu` <6.1.5 prototype pollution (CVE-2026-35209)
- VG1003 — High: Hono ErrorBoundary XSS before v4.11.7
- VG1004 — Medium: React Server Action without rate limiting (CVE-2026-23864)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]