PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder (CVE-2026-57120) | HOL Guard CVE