aqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outside the install directory (CVE-2026-55569) | HOL Guard CVE