Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications (CVE-2026-13601) | HOL Guard CVE