pip's fallback tar extraction doesn't check symbolic links point to extraction directory (CVE-2025-8869) | HOL Guard CVE