Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing (CVE-2026-66066) | HOL Guard CVE