Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass (CVE-2026-53609) | HOL Guard CVE