Kyoo: OIDC login token can be redirected to an attacker-controlled URL (CVE-2026-77386) | HOL Guard CVE