Trigger.dev: Cross-tenant object store read and write via URL path traversal (CVE-2026-73658) | HOL Guard CVE