GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby Driver (CVE-2026-88030) | HOL Guard CVE