0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection (CVE-2026-90690) | HOL Guard CVE