vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape (CVE-2026-43999) | HOL Guard CVE