Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access (CVE-2026-58438) | HOL Guard CVE