Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline (CVE-2026-77912) | HOL Guard CVE