This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort v3.7.0 adds detection rules for three critical CVEs: DOMPurify XSS, Better Auth device‑authorization bypass (RCE risk), and React Router 7 vulnerabilities (XSS/deserialization/RCE/DoS).
Why it matters: CVE severity scores exceed 95; immediate monitoring is required to protect applications using these libraries.
Summary
AI summaryAdds three fresh CVE detection rules for DOMPurify XSS, React Router 7 vulnerabilities, and Better Auth device‑authorization bypass.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches CVE-2026-47423 DOMPurify XSS vulnerability. Patches CVE-2026-47423 DOMPurify XSS vulnerability. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Security | Critical |
Patches CVE-2026-45337 Better Auth device‑authorization bypass (RCE risk). Patches CVE-2026-45337 Better Auth device‑authorization bypass (RCE risk). Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Security | Critical |
Patches CVE-2026 React Router 7 cluster (XSS / deserialization RCE / DoS). Patches CVE-2026 React Router 7 cluster (XSS / deserialization RCE / DoS). Source: llm_adapter@2026-06-07 Confidence: high |
— |
Full changelog
- 3 fresh CVE rules from the daily intel pipeline — June 2026 advisories for mainstream libraries: DOMPurify XSS (CVE-2026-47423), React Router 7 cluster (XSS / deserialization RCE / DoS), and Better Auth device-authorization bypass (CVE-2026-45337)
- Precise semver matching: a caret/tilde range that resolves to the fixed patch is not flagged; validated 0 false positives across the corpus, 22 new version-range tests
- 441 rules / 37 tools; gate green (PASS/A/0)
Security Fixes
- dep: CVE-2026-47423 — DOMPurify XSS vulnerability
- dep: CVE-2026-45337 — Better Auth device‑authorization bypass
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]