TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` (CVE-2026-47099) | HOL Guard CVE