Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path (CVE-2026-55798) | HOL Guard CVE