Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter (CVE-2026-54021) | HOL Guard CVE