league/commonmark contains an XSS vulnerability in the Attributes extension I just installed the package into a new project and see that it contains a dependency with a registered CVE as of May 15th, 2025. 