This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Light signalVite dev-server on Windows had a command injection flaw in versions <5.4.9 and launch-editor <2.9.0; it is fixed in the release.
Why it matters: Addresses CVE-2024-52011 (severity 95) affecting vite <5.4.9 and launch-editor <2.9.0 on Windows – upgrade immediately to mitigate injection risk.
Summary
AI summaryCVE-2024-52011 dev-server command injection vulnerability fixed
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes command injection vulnerability in vite <5.4.9 and launch-editor <2.9.0 on Windows. Fixes command injection vulnerability in vite <5.4.9 and launch-editor <2.9.0 on Windows. Source: llm_adapter@2026-06-08 Confidence: high |
— |
Full changelog
- VG1088: vite < 5.4.9 (and bundled launch-editor < 2.9.0) dev-server command injection on Windows (CVE-2024-52011) — surfaced by daily intel, drafted via the scaffold pipeline
- Exact-pin only (0-FP: caret/tilde resolve to the fix); validated on the corpus with 1 true positive and 0 false positives
- 442 rules / 37 tools; gate green (PASS/A/0)
Security Fixes
- CVE-2024-52011 — dev-server command injection vulnerability fixed by requiring vite >= 5.4.9 and launch-editor >= 2.9.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]