Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer (CVE-2026-55105) | HOL Guard CVE