OpenClaw: Bootstrap token replay could widen pending pairing scopes (CVE-2026-53862) | HOL Guard CVE