OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install (CVE-2026-53846) | HOL Guard CVE