BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py (CVE-2026-54071) | HOL Guard CVE