pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes (CVE-2026-55698) | HOL Guard CVE