Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis (CVE-2026-88069) | HOL Guard CVE