This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryCVE-2026-48713 and CVE-2026-48714 fix critical i18next prototype‑pollution vulnerabilities
Full changelog
Daily intel: 1 new rule. VG1097 — i18next missing-key prototype pollution (CVE-2026-48713 i18next-fs-backend < 2.6.6, CVE-2026-48714 i18next-http-middleware < 3.9.7, both critical, published 2026-06-25). Distinct from the existing i18next-http-backend path-traversal rule. 0-FP semver (caret on the current major and tilde within the fixed minor resolve to the patch). 451 rules / 39 tools / 78 CVE rules. 16 tests.
Security Fixes
- CVE-2026-48713 — prototype pollution in i18next-fs-backend versions < 2.6.6 (critical)
- CVE-2026-48714 — prototype pollution in i18next-http-middleware versions < 3.9.7 (critical)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]