Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload (CVE-2026-48063) | HOL Guard CVE