RestrictedPython: Sandbox escape via string.Formatter field resolution (CVE-2026-76825) | HOL Guard CVE