2.5
CVSS V3
Status
Impact
The vulnerability originates from a pinned dependency version that is also consumed by other libraries within the dependency graph. Upstream must update this dependency to a secure version and reconcile any resulting compatibility issues across the dependency tree. Once these changes are implemented upstream, the vulnerability can be remediated accordingly.
Status