FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP) (CVE-2026-54521) | HOL Guard CVE