AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory (CVE-2026-54520) | HOL Guard CVE