SVGO: removeScripts allows executable links through namespace and control-character bypasses (CVE-2026-84370) | HOL Guard CVE