Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) (CVE-2026-67429) | HOL Guard CVE