OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks (CVE-2026-53834) | HOL Guard CVE