SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover (CVE-2026-44648) | HOL Guard CVE