LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` (CVE-2026-44646) | HOL Guard CVE