Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() (CVE-2026-55890) | HOL Guard CVE