Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read (CVE-2026-47661) | HOL Guard CVE