Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo (CVE-2026-87114) | HOL Guard CVE