Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345) (CVE-2026-57171) | HOL Guard CVE