Skip to content

goklab/guardvibe

v3.28.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

deps

Summary

AI summary

CVE-2026-48713 and CVE-2026-48714 fix critical i18next prototype‑pollution vulnerabilities

Full changelog

Daily intel: 1 new rule. VG1097 — i18next missing-key prototype pollution (CVE-2026-48713 i18next-fs-backend < 2.6.6, CVE-2026-48714 i18next-http-middleware < 3.9.7, both critical, published 2026-06-25). Distinct from the existing i18next-http-backend path-traversal rule. 0-FP semver (caret on the current major and tilde within the fixed minor resolve to the patch). 451 rules / 39 tools / 78 CVE rules. 16 tests.

Security Fixes

  • CVE-2026-48713 — prototype pollution in i18next-fs-backend versions < 2.6.6 (critical)
  • CVE-2026-48714 — prototype pollution in i18next-http-middleware versions < 3.9.7 (critical)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Related context

Beta — feedback welcome: [email protected]