default-import vulnerabilities

Properly handle CJS imports in ESM.