rails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PTY Escape (CVE-2026-81097) | HOL Guard CVE