Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders (CVE-2026-54499) | HOL Guard CVE