Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hook (CVE-2026-54510) | HOL Guard CVE