Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name (CVE-2026-46634) | HOL Guard CVE