Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID (CVE-2026-54695) | HOL Guard CVE