Skip to content

Npm

CVE-2026-41265 - Flowise Airtable Agent code injection RCE

May 2, 2026

CVE-2026-41478 - Saltcorn mobile-sync SQL injection

May 2, 2026

GHSA-3xx2/GHSA-47wq - Paperclip agent key tenant-boundary bypass

May 2, 2026

GHSA-vr7g-88fq-vhq3 - Paperclip workspace cleanup command injection

May 2, 2026

CVE-2026-41507 - math-codegen string literal RCE

May 2, 2026

CVE-2026-42449 - n8n-mcp IPv4-mapped IPv6 SSRF

May 2, 2026

CVE-2026-42231 - n8n XML webhook prototype pollution RCE

May 2, 2026

CVE-2026-42232 - n8n XML node prototype pollution RCE

May 2, 2026

CVE-2026-42349 - Clerk combined authorization bypass

May 3, 2026

GHSA-xh72/GHSA-xmxx - OpenClaw agent-surface fail-closed bypasses

May 2, 2026