NpmCVE-2026-41265 - Flowise Airtable Agent code injection RCEMay 2, 2026CVE-2026-41478 - Saltcorn mobile-sync SQL injectionMay 2, 2026GHSA-3xx2/GHSA-47wq - Paperclip agent key tenant-boundary bypassMay 2, 2026GHSA-vr7g-88fq-vhq3 - Paperclip workspace cleanup command injectionMay 2, 2026CVE-2026-41507 - math-codegen string literal RCEMay 2, 2026CVE-2026-42449 - n8n-mcp IPv4-mapped IPv6 SSRFMay 2, 2026CVE-2026-42231 - n8n XML webhook prototype pollution RCEMay 2, 2026CVE-2026-42232 - n8n XML node prototype pollution RCEMay 2, 2026CVE-2026-42349 - Clerk combined authorization bypassMay 3, 2026GHSA-xh72/GHSA-xmxx - OpenClaw agent-surface fail-closed bypassesMay 2, 2026