Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass (CVE-2026-54166) | HOL Guard CVE