docs(security): update threat-db v2.5.0 + security-hardening CVE table
threat-db.yaml:
- 6 new CVEs: CVE-2026-25253 (OpenClaw 1-click RCE, CVSS 8.8),
CVE-2026-25725 (Claude Code sandbox escape), CVE-2026-3484
(nmap-mcp-server cmd injection), CVE-2025-35028 (HexStrike critical
9.1, no patch), CVE-2025-15061 (Figma MCP critical 9.8),
CVE-2026-0757 (MCP Manager sandbox escape)
- T013: Autonomous Safety Control Bypass (Ona research, 2026-03-03)
- openclaw v2026.1.29 added to minimum_safe_versions
- 10 new sources, version bump 2.4.0 → 2.5.0
security-hardening.md:
- CVE table extended from 9 to 15 entries
- Callouts added for 4 critical/unpatched CVEs
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>