Goomph before 3.37.2 allows malicious zip file to write contents to arbitrary locations (CVE-2022-26049) | HOL Guard CVE