Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user (CVE-2026-54618) | HOL Guard CVE