Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href (CVE-2026-25500) | HOL Guard CVE