ByteDance DeerFlow Path Traversal and Arbitrary File Write via Bootstrap Mode (CVE-2026-40518) | HOL Guard CVE