SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon (CVE-2026-54068) | HOL Guard CVE