v2.0: Framework CVEs, supply chain/slopsquatting, MCP security, tooling (2025-2026) - #2
Open
fartiacht wants to merge 1 commit into
Open
v2.0: Framework CVEs, supply chain/slopsquatting, MCP security, tooling (2025-2026)#2fartiacht wants to merge 1 commit into
fartiacht wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates vibe-security with vulnerabilities, attack patterns, and tooling from 2025–2026.
3 new reference files:
framework-versions.md— Critical CVEs: React2Shell (CVSS 10.0), Next.js middleware bypass (CVSS 9.1)supply-chain.md— Slopsquatting, hallucinated packages, default AI-generated credentialstooling.md— Automated security tools by stack (gitleaks, Supabase Security Advisor, etc.)5 updated reference files:
database-security.md— Supabase Edge Functions, MCP + service_role vulnerability, new API key modelauthentication.md— Middleware as NOT a security boundary (with CVE refs), passkeys,import 'server-only'ai-integration.md— MCP security, AI billing circuit breakersdeployment.md— Vercel preview deployments as attack surfacesecrets-and-env.md— AI-generated default credentials, new Supabase key modelAudit process: 9 → 11 steps. Framework version check is now step 1. New supply chain step. Output includes "Next Steps" with specific tools.
Total content: +52% (772 → 1,176 lines across references).
Sources: Escape.tech (5,600 vibe-coded apps study), Supabase Security Retro 2025, Next.js/React CVE advisories, Aikido Security (slopsquatting research), Unit 42 (Palo Alto).