swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template (CVE-2026-54661) | HOL Guard CVE