Vite allows server.fs.deny to be bypassed with .svg or relative paths (CVE-2025-31486) | HOL Guard CVE