Skip to content

v2.0: Framework CVEs, supply chain/slopsquatting, MCP security, tooling (2025-2026) - #2

Open
fartiacht wants to merge 1 commit into
raroque:mainfrom
fartiacht:v2-2026-updates
Open

v2.0: Framework CVEs, supply chain/slopsquatting, MCP security, tooling (2025-2026)#2
fartiacht wants to merge 1 commit into
raroque:mainfrom
fartiacht:v2-2026-updates

Conversation

@fartiacht

Copy link
Copy Markdown

Updates vibe-security with vulnerabilities, attack patterns, and tooling from 2025–2026.

3 new reference files:

  • framework-versions.md — Critical CVEs: React2Shell (CVSS 10.0), Next.js middleware bypass (CVSS 9.1)
  • supply-chain.md — Slopsquatting, hallucinated packages, default AI-generated credentials
  • tooling.md — Automated security tools by stack (gitleaks, Supabase Security Advisor, etc.)

5 updated reference files:

  • database-security.md — Supabase Edge Functions, MCP + service_role vulnerability, new API key model
  • authentication.md — Middleware as NOT a security boundary (with CVE refs), passkeys, import 'server-only'
  • ai-integration.md — MCP security, AI billing circuit breakers
  • deployment.md — Vercel preview deployments as attack surface
  • secrets-and-env.md — AI-generated default credentials, new Supabase key model

Audit process: 9 → 11 steps. Framework version check is now step 1. New supply chain step. Output includes "Next Steps" with specific tools.

Total content: +52% (772 → 1,176 lines across references).

Sources: Escape.tech (5,600 vibe-coded apps study), Supabase Security Retro 2025, Next.js/React CVE advisories, Aikido Security (slopsquatting research), Unit 42 (Palo Alto).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant