Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration (CVE-2025-67492) | HOL Guard CVE