Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist (CVE-2026-93759) | HOL Guard CVE