@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata (CVE-2026-61782) | HOL Guard CVE