SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements (CVE-2026-84369) | HOL Guard CVE