Composer is vulnerable to Command Injection via Malicious Perforce Repository (CVE-2026-40176) | HOL Guard CVE