Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query (CVE-2025-31125) | HOL Guard CVE