Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows (CVE-2026-49449) | HOL Guard CVE