FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix (CVE-2026-59973) | HOL Guard CVE