Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing (CVE-2026-61539) | HOL Guard CVE