Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions (CVE-2026-49406) | HOL Guard CVE