Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL (CVE-2026-53722) | HOL Guard CVE