Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution (CVE-2026-45018) | HOL Guard CVE