Snappy: Binary path is never shell-escaped due to an inverted is_executable check (CVE-2026-46643) | HOL Guard CVE