sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes (CVE-2026-59894) | HOL Guard CVE