PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint (CVE-2026-57128) | HOL Guard CVE