code16/sharp has a stored XSS via data-html-content Sanitizer Bypass (CVE-2026-61825) | HOL Guard CVE