OpenClaw: Host environment sanitizer missed two Node.js control variables (CVE-2026-53864) | HOL Guard CVE