@cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNode (CVE-2026-30691) | HOL Guard CVE