STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library (CVE-2026-77710) | HOL Guard CVE