Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup (CVE-2026-97228) | HOL Guard CVE