JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) (CVE-2026-73417) | HOL Guard CVE