label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter. (CVE-2025-47783) | HOL Guard CVE