npm›@diplodoc/search-extension›CVE-2026-402015.4 MEDIUM@diplodoc/search-extension allows stored XSS via Markdown file title@diplodoc/search-extension 1.0.0 through 3.0.2 allows stored XSS via .md file title.