Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX/XLSX conversion) (CVE-2026-93405) | HOL Guard CVE