swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template (CVE-2026-54662) | HOL Guard CVE