Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()` (CVE-2026-44635) | HOL Guard CVE