Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input (CVE-2026-54163) | HOL Guard CVE