CRITICAL9.8PackagistnpmGHSA-wjc4-73q6-gv3m· CVE-2023-46308plotly.js prototype pollution vulnerabilityModified: 12/26/2025