draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46642 (CVE-2026-58504) | HOL Guard CVE