File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection (CVE-2026-54090) | HOL Guard CVE