sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes (CVE-2026-53606) | HOL Guard CVE