0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal (CVE-2026-90691) | HOL Guard CVE