@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper (CVE-2026-46672) | HOL Guard CVE