Skip to content

goklab/guardvibe

v3.14.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 4d MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

rce_ssrf

ReleasePort's take

Light signal
editorial:auto 4d

Vite dev-server on Windows had a command injection flaw in versions <5.4.9 and launch-editor <2.9.0; it is fixed in the release.

Why it matters: Addresses CVE-2024-52011 (severity 95) affecting vite <5.4.9 and launch-editor <2.9.0 on Windows – upgrade immediately to mitigate injection risk.

Summary

AI summary

CVE-2024-52011 dev-server command injection vulnerability fixed

Changes in this release

Security Critical

Fixes command injection vulnerability in vite <5.4.9 and launch-editor <2.9.0 on Windows.

Fixes command injection vulnerability in vite <5.4.9 and launch-editor <2.9.0 on Windows.

Source: llm_adapter@2026-06-08

Confidence: high

Full changelog
  • VG1088: vite < 5.4.9 (and bundled launch-editor < 2.9.0) dev-server command injection on Windows (CVE-2024-52011) — surfaced by daily intel, drafted via the scaffold pipeline
  • Exact-pin only (0-FP: caret/tilde resolve to the fix); validated on the corpus with 1 true positive and 0 false positives
  • 442 rules / 37 tools; gate green (PASS/A/0)

Security Fixes

  • CVE-2024-52011 — dev-server command injection vulnerability fixed by requiring vite >= 5.4.9 and launch-editor >= 2.9.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Beta — feedback welcome: [email protected]