systeminformation has Command Injection via Unsanitized `locate` Output in `versions()` (CVE-2026-26318) | HOL Guard CVE