Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory (CVE-2026-80430) | HOL Guard CVE