AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL (CVE-2026-45578) | HOL Guard CVE