OpenClaw: Pairing-scoped device session could restore revoked node token authority (CVE-2026-53843) | HOL Guard CVE