Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments (CVE-2026-72878) | HOL Guard CVE