jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin (CVE-2025-9910) | HOL Guard CVE