OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API (CVE-2026-69160) | HOL Guard CVE