Skip to content

goklab/guardvibe

v3.0.21 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
gemini-cli-extension hono mcp nextjs owasp prisma static-analysis security stripe supabase supply-chain typescript vercel vibe-coding

Affected surfaces

auth rce_ssrf deps

Summary

AI summary

Security fixes for Clerk route bypass, Next.js RSC DoS, and multiple critical vulnerabilities including an Axios backdoor and Drizzle SQL injection.

Full changelog
  • VG925: Clerk middleware route protection bypass (GHSA-vqx2)
  • VG926: Next.js / React RSC DoS (CVE-2026-23869)
  • VG923/924/1010/1011: Axios backdoor, Hono CRLF, React Server Action validation, Drizzle SQL injection (CVE-2026-39356)

Security Fixes

  • VG925 – Clerk middleware route protection bypass (GHSA-vqx2)
  • VG926 – Next.js / React RSC Denial‑of‑Service (CVE-2026-23869)
  • VG923/924/1010/1011 – Axios backdoor, Hono CRLF injection, React Server Action validation flaw, Drizzle SQL injection (CVE-2026-39356)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Beta — feedback welcome: [email protected]