GitHub CLI: Unescaped variable components in request URLs could allow path traversal (CVE-2026-64653) | HOL Guard CVE