js-toml has silent type confusion via falsy-primitive duplicate-key bypass (CVE-2026-50029) | HOL Guard CVE