Skip to content

goklab/guardvibe

v3.30.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 12d MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 12d

ReleasePort Layer 1 v3.30.0 adds IOC rules targeting malicious npm releases (jscrambler 8.14.0‑8.20.0) and a @injectivelabs/sdk-ts wallet‑key backdoor, plus a version‑pin rule for n8n-mcp's CVE‑2026-54052.

Why it matters: The new IOC rules immediately block known compromised npm packages (jscrambler 8.14.0‑8.20.0 and @injectivelabs/sdk-ts 1.20.21) and enforce pinning for n8n-mcp to mitigate CVE‑2026-54052.

Summary

AI summary

Added IOC rules for npm supply‑chain compromises and a version‑pin rule addressing CVE-2026-54052.

Changes in this release

Security Critical

Adds IOC rule for jscrambler malicious npm releases (8.14.0‑8.20.0)

Adds IOC rule for jscrambler malicious npm releases (8.14.0‑8.20.0)

Source: llm_adapter@2026-07-15

Confidence: high

Security Critical

Adds IOC rule for @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor

Adds IOC rule for @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Adds version‑pin rule for n8n-mcp cross‑tenant access (CVE-2026-54052)

Adds version‑pin rule for n8n-mcp cross‑tenant access (CVE-2026-54052)

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Maps July Hono disclosures (CVE-2026-56763, CVE-2026-56762) into existing rules

Maps July Hono disclosures (CVE-2026-56763, CVE-2026-56762) into existing rules

Source: llm_adapter@2026-07-15

Confidence: high

Security High

Maps Anthropic SDK memory‑tool CVE IDs into existing rules without duplicates

Maps Anthropic SDK memory‑tool CVE IDs into existing rules without duplicates

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog
  • New IOC rules for two active npm supply-chain compromises: jscrambler malicious releases (8.14.0/8.16.0/8.17.0/8.18.0/8.20.0) and @injectivelabs/sdk-ts 1.20.21 wallet-key backdoor
  • New version-pin rule for n8n-mcp multi-tenant cross-tenant access (CVE-2026-54052, fixed in 2.56.1)
  • July Hono disclosures (CVE-2026-56763/56762) and Anthropic SDK memory-tool CVE ids mapped into existing rules — no duplicates

Security Fixes

  • CVE-2026-54052 — fixed in n8n-mcp version 2.56.1 via new version‑pin rule
  • CVE-2026-56763 and CVE-2026-56762 (July Hono disclosures) mapped into existing rules

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]