@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag (CVE-2026-53608) | HOL Guard CVE