Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing (CVE-2026-48788) | HOL Guard CVE