@platejs/core HTML deserialization can trigger browser behavior during parsing (CVE-2026-88976) | HOL Guard CVE