SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials (CVE-2026-33311) | HOL Guard CVE