claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh (CVE-2026-45136) | HOL Guard CVE