Weblate: Mercurial argument injection via repository filenames allows authenticated command execution (CVE-2026-86035) | HOL Guard CVE