Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage (CVE-2026-53728) | HOL Guard CVE