SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path (CVE-2026-63735) | HOL Guard CVE