LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints (CVE-2026-103243) | HOL Guard CVE