MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip (CVE-2026-85061) | HOL Guard CVE