Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab (CVE-2025-9222) | HOL Guard CVE