FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser (CVE-2026-73235) | HOL Guard CVE