Reachy Mini daemon allows unauthenticated remote code execution through the app installation endpoint (CVE-2026-96455) | HOL Guard CVE