JFrog's Xray is still making the latest version of this package (6.2.4) as vulnerable to the following CVEs. I'm not sure where these deps are getting pulled from, but they should be updated.
CVE-2023-49568
CVE-2023-49569
CVE-2025-21613
CVE-2025-21614
CVE-2025-22868
CVE-2025-22869