HIGHnpmGHSA-95jq-xph2-cx9h· CVE-2025-8101Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)Modified: 9/10/2026