esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files (CVE-2026-44594) | HOL Guard CVE