ERPNext: Possibility of server-side template injection due to missing validation (CVE-2026-72911) | HOL Guard CVE