Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing (CVE-2026-72720) | HOL Guard CVE