CVE-2026-2256: Command Injection in ModelScope MS-Agent | NextGuard