@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution (CVE-2026-54658) | HOL Guard CVE