This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 v3.30.0 adds IOC rules targeting malicious npm releases (jscrambler 8.14.0‑8.20.0) and a @injectivelabs/sdk-ts wallet‑key backdoor, plus a version‑pin rule for n8n-mcp's CVE‑2026-54052.
Why it matters: The new IOC rules immediately block known compromised npm packages (jscrambler 8.14.0‑8.20.0 and @injectivelabs/sdk-ts 1.20.21) and enforce pinning for n8n-mcp to mitigate CVE‑2026-54052.
Summary
AI summaryAdded IOC rules for npm supply‑chain compromises and a version‑pin rule addressing CVE-2026-54052.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds IOC rule for jscrambler malicious npm releases (8.14.0‑8.20.0) Adds IOC rule for jscrambler malicious npm releases (8.14.0‑8.20.0) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Adds IOC rule for @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor Adds IOC rule for @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Adds version‑pin rule for n8n-mcp cross‑tenant access (CVE-2026-54052) Adds version‑pin rule for n8n-mcp cross‑tenant access (CVE-2026-54052) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Maps July Hono disclosures (CVE-2026-56763, CVE-2026-56762) into existing rules Maps July Hono disclosures (CVE-2026-56763, CVE-2026-56762) into existing rules Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
Maps Anthropic SDK memory‑tool CVE IDs into existing rules without duplicates Maps Anthropic SDK memory‑tool CVE IDs into existing rules without duplicates Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
- New IOC rules for two active npm supply-chain compromises: jscrambler malicious releases (8.14.0/8.16.0/8.17.0/8.18.0/8.20.0) and @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor
- New version-pin rule for n8n-mcp multi-tenant cross-tenant access (CVE-2026-54052, fixed in 2.56.1)
- July Hono disclosures (CVE-2026-56763/56762) and Anthropic SDK memory-tool CVE ids mapped into existing rules — no duplicates
Security Fixes
- CVE-2026-54052 — fixed in n8n-mcp version 2.56.1 via new version‑pin rule
- CVE-2026-56763 and CVE-2026-56762 (July Hono disclosures) mapped into existing rules
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Beta — feedback welcome: [email protected]