Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling (CVE-2026-73682) | HOL Guard CVE