Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection (CVE-2026-41149) | HOL Guard CVE