Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge (CVE-2026-63297) | HOL Guard CVE