SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol (CVE-2026-66395) | HOL Guard CVE