Open WebUI: Stored XSS to Account Takeover via Model Profile Images (CVE-2026-54013) | HOL Guard CVE