parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist (CVE-2026-55778) | HOL Guard CVE