Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults (CVE-2026-54053) | HOL Guard CVE