swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` (CVE-2026-54663) | HOL Guard CVE