pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install (CVE-2026-82393) | HOL Guard CVE