HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection (CVE-2026-102874) | HOL Guard CVE