Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client (CVE-2026-48996) | HOL Guard CVE