This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryCritical security fixes for deepstream server prototype pollution and pnpm path‑traversal/RCE vulnerabilities.
Full changelog
- VG1098 — @deepstream/server <10.0.5 prototype pollution (CVE-2026-49252, critical CVSS 9.9)
- VG1099 — pnpm lockfile/manifest path-traversal & RCE cluster, flags Corepack packageManager pin <10.34.2 / 11.0–11.5.2 (CVE-2026-55698, -55487, -50016 et al.)
- 453 rules / 80 CVE rules / 39 tools; 0-FP semver, 33 new tests, gate PASS/A/0
Security Fixes
- CVE-2026-49252 — deepstream/server <10.0.5 prototype pollution (critical, CVSS 9.9)
- CVE-2026-55698, CVE-2026-55487, CVE-2026-50016 — pnpm lockfile/manifest path‑traversal & RCE cluster; require Corepack packageManager pin <10.34.2 or >=11.5.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]