QWED: Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` (CVE-2026-55585) | HOL Guard CVE