Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories (CVE-2026-35397) | HOL Guard CVE