mcp-from-openapi: Bypass of OpenAPI external $ref SSRF fix in latest FrontMCP and mcp-from-openapi (CVE-2026-59973) | HOL Guard CVE