Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038) (CVE-2026-46709) | HOL Guard CVE