QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input (CVE-2026-55546) | HOL Guard CVE