@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) (CVE-2026-54265) | HOL Guard CVE