GhsaGHSA-3xx2/GHSA-47wq - Paperclip agent key tenant-boundary bypassMay 2, 2026GHSA-vr7g-88fq-vhq3 - Paperclip workspace cleanup command injectionMay 2, 2026GHSA-v4p8-mg3p-g94g - LiteLLM MCP stdio command executionMay 2, 2026GHSA-rpm5/GHSA-x2qx - GitPython command injectionMay 2, 2026GHSA-rh99-wc69-c255 - Contrast CopyFile policy symlink subversionMay 3, 2026GHSA-74m3 - zrok WebDAV DriveRoot symlink escapeMay 2, 2026GHSA-xh72/GHSA-xmxx - OpenClaw agent-surface fail-closed bypassesMay 2, 2026