Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab (CVE-2026-6896) | HOL Guard CVE