CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration (CVE-2026-41249) | HOL Guard CVE