pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal (CVE-2026-45348) | HOL Guard CVE