TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner (CVE-2026-54505) | HOL Guard CVE