Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter (CVE-2026-45626) | HOL Guard CVE