GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP Library (CVE-2026-88023) | HOL Guard CVE