Zammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcset (CVE-2026-63006) | HOL Guard CVE