Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients (CVE-2026-76842) | HOL Guard CVE