SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history (CVE-2026-61614) | HOL Guard CVE