swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` (CVE-2026-54660) | HOL Guard CVE