mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable (CVE-2026-55581) | HOL Guard CVE