calibre: Bypass of Python template restrictions via nested `template()` leading to RCE (CVE-2026-73248) | HOL Guard CVE