v3.24.0
1 rule from daily threat intel (449 → 450 rules).
- VG1096 — @clerk/nextjs 4.x auth()/getAuth() IDOR (CVE-2024-22206 / GHSA-q6w5-jg5q-47vg, critical). Versions 4.7.0–4.29.2 misattribute a request to the wrong session (IDOR / privilege escalation); fixed in 4.29.3. Fills the legacy 4.x version-space not covered by the 1.x/2.x (VG925) or 6.x/7.x (VG1045) Clerk pins. 0-FP semver (caret/tilde-within-4.29 resolve to the fix).
Verified already-covered (no action) from the brief: install-time dropper signature (supply-chain.ts 'Install Script Downloads and Executes Remote Code' + Miasma IOC + CI --ignore-scripts), axios user-URL SSRF (taint sink + VG120), Clerk CVE-2026-42349/41248 (VG1045/VG925), Next.js RSC cluster (VG1047).