OpenClaw: Empty-scope device re-pairing could confuse caller scope containment (CVE-2026-53852) | HOL Guard CVE