browse-mcp: Arbitrary file write via unconfined download and state paths (CVE-2026-55557) | HOL Guard CVE