@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header (CVE-2026-53607) | HOL Guard CVE