XSS during SSR with contenteditable `bind:innerText` and `bind:textContent` (CVE-2026-27901) | HOL Guard CVE