Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory (CVE-2026-55569) | HOL Guard CVE