pnpm vulnerable to Command Injection via environment variable substitution (CVE-2025-69262) | HOL Guard CVE