CVE-2025-11945: XSS in AFFiNE Avatar Upload Endpoint | NextGuard