Skip to content

goklab/guardvibe

v3.1.26 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

auth rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 1mo

Release v3.1.26 patches three critical security issues: an axios proxy‑auth redirect leak (CVE-2026-44486/87), a Hono setCookie attribute injection flaw (CVE-2026-47675), and a Drizzle SQL injection vulnerability.

Why it matters: All listed CVEs have high severity; immediate patching prevents information leakage, cookie hijacking, and SQL injection attacks. Deploy v3.1.26 to mitigate these risks.

Summary

AI summary

Fixes CVE-2026-44486/87, CVE-2026-47675 and a Drizzle SQL injection vulnerability.

Changes in this release

Security Critical

Fixes axios proxy-auth redirect information leak (CVE-2026-44486/87).

Fixes axios proxy-auth redirect information leak (CVE-2026-44486/87).

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Fixes hono setCookie attribute injection vulnerability (CVE-2026-47675).

Fixes hono setCookie attribute injection vulnerability (CVE-2026-47675).

Source: llm_adapter@2026-06-06

Confidence: high

Security Critical

Addresses Miasma @redhat-cloud-services namespace IOC issue (RHSB-2026-006).

Addresses Miasma @redhat-cloud-services namespace IOC issue (RHSB-2026-006).

Source: llm_adapter@2026-06-06

Confidence: high

Dependency Medium

Patches hono, brace-expansion, and qs via npm audit fix.

Patches hono, brace-expansion, and qs via npm audit fix.

Source: llm_adapter@2026-06-06

Confidence: high

Full changelog
  • VG1071-1073: axios proxy-auth redirect leak (CVE-2026-44486/87), hono setCookie attribute injection (CVE-2026-47675), drizzle sql.raw/sql.identifier interpolation
  • VG1074-1075: Miasma @redhat-cloud-services namespace IOC (RHSB-2026-006), Session messenger filev2.getsession.org exfil endpoint
  • npm audit fix: hono / brace-expansion / qs patched; hono override floor bumped to ^4.12.21; self-audit PASS A 100

Security Fixes

  • CVE-2026-44486 — axios proxy‑auth redirect leak
  • CVE-2026-44487 — axios proxy‑auth redirect leak (second variant)
  • CVE-2026-47675 — Hono setCookie attribute injection

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]