Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access (CVE-2026-45019) | HOL Guard CVE