Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin (CVE-2026-70486) | HOL Guard CVE