yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output (CVE-2026-55404) | HOL Guard CVE