Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader (CVE-2026-70479) | HOL Guard CVE