@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input (CVE-2026-42853) | HOL Guard CVE