Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied Data (CVE-2013-4170) | HOL Guard CVE