Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242) (CVE-2026-61792) | HOL Guard CVE