lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out (CVE-2026-46517) | HOL Guard CVE