SECURITY UPDATE: Command injection in netbeans interface
debian/patches/CVE-2026-39881.patch: add nbissafestring() in
src/netbeans.c and validate typeName, fg and bg in defineAnnoType
and key tokens in specialkeys() against an allowlist before they
reach coloncmd()/do_map(), preventing a malicious netbeans server
from injecting Ex commands via '|'