CVE-2026-39977: flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files — Zero Day Monitor