Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS (CVE-2026-62324) | HOL Guard CVE