Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletion (CVE-2026-48070) | HOL Guard CVE