Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController) (CVE-2026-73427) | HOL Guard CVE