tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape (CVE-2026-44705) | HOL Guard CVE