swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies (CVE-2026-54666) | HOL Guard CVE