Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory (CVE-2026-49453) | HOL Guard CVE