SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity (CVE-2026-81178) | HOL Guard CVE