Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author) (CVE-2026-41580) | HOL Guard CVE