Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter (CVE-2026-63408) | HOL Guard CVE