gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host (CVE-2026-49340) | HOL Guard CVE