GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python Driver (CVE-2026-88029) | HOL Guard CVE