Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass (CVE-2026-59163) | HOL Guard CVE