compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal (CVE-2026-45725) | HOL Guard CVE