DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content (CVE-2026-49978) | HOL Guard CVE