Skip to content

v3.23.0

Choose a tag to compare

@goklab goklab released this 19 Jun 20:00

2 rules from daily threat intel (448 → 449 rules).

  • VG1095 — MCP / agent tool-call endpoint without authentication (high). Flags HTTP routes exposing MCP tools/call, /mcp, or agent run/invoke/execute with no auth guard near the registration. Targets the June-2026 wave: praisonai, network-ai, AgenticMail.
  • VG1094 extended to full CVE-2026-54290 coverage: now also flags cors({ origin:'*', credentials:true }) and credentials:true with no origin key. VG973 narrowed so the two are mutually exclusive.

Verified already-covered (no action): axios CVE-2026-44489/44490/44496 (fixed 1.16.0), next RSC cluster, Clerk/Drizzle/js-cookie/postcss. 0 false positives across 21,585 corpus files.