Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget (CVE-2026-45012) | HOL Guard CVE