Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` (CVE-2026-44990) | HOL Guard CVE