sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock (CVE-2026-73567) | HOL Guard CVE