LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS (CVE-2026-44644) | HOL Guard CVE