Package URLs can be used to exfiltrate arbitrary INI file values and environment variables (CVE-2026-63278) | HOL Guard CVE