CVE-2026-22174: Token Injection in OpenClaw | NextGuard