Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} (CVE-2026-47659) | HOL Guard CVE