Svelte SSR vulnerable to cross-site scripting via spread attributes (CVE-2026-42599) | HOL Guard CVE