morgan vulnerable to Log Injection via unescaped double quote in quoted log fields (CVE-2026-87859) | HOL Guard CVE