Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature (CVE-2026-53580) | HOL Guard CVE