Updated `sanitizeElement` to strictly remove whitespace and control characters from URI attributes before validation. This prevents bypasses like `java\tscript:` in `href`, `src`, `action`, and `formaction` attributes. Added comprehensive unit tests covering these bypass vectors. Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>