Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter (CVE-2026-73037) | HOL Guard CVE