@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString (CVE-2026-50290) | HOL Guard CVE