Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin (CVE-2026-87995) | HOL Guard CVE