Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE (CVE-2026-45805) | HOL Guard CVE