BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver (CVE-2025-10281) | HOL Guard CVE