Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CVE-2026-48030) | HOL Guard CVE