OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool (CVE-2026-75602) | HOL Guard CVE