OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting (CVE-2026-77601) | HOL Guard CVE