@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme (CVE-2023-34245) | HOL Guard CVE