JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) (CVE-2026-102830) | HOL Guard CVE