Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive (CVE-2026-50558) | HOL Guard CVE