Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps (CVE-2026-55431) | HOL Guard CVE