Skip to content

goklab/guardvibe

v3.29.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 29d MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

rce_ssrf deps breaking_upgrade

Summary

AI summary

Critical security fixes for deepstream server prototype pollution and pnpm path‑traversal/RCE vulnerabilities.

Full changelog
  • VG1098 — @deepstream/server <10.0.5 prototype pollution (CVE-2026-49252, critical CVSS 9.9)
  • VG1099 — pnpm lockfile/manifest path-traversal & RCE cluster, flags Corepack packageManager pin <10.34.2 / 11.0–11.5.2 (CVE-2026-55698, -55487, -50016 et al.)
  • 453 rules / 80 CVE rules / 39 tools; 0-FP semver, 33 new tests, gate PASS/A/0

Security Fixes

  • CVE-2026-49252 — deepstream/server <10.0.5 prototype pollution (critical, CVSS 9.9)
  • CVE-2026-55698, CVE-2026-55487, CVE-2026-50016 — pnpm lockfile/manifest path‑traversal & RCE cluster; require Corepack packageManager pin <10.34.2 or >=11.5.3

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Related context

Beta — feedback welcome: [email protected]