Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries (CVE-2026-48921) | HOL Guard CVE