piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env (CVE-2026-102992) | HOL Guard CVE