All the vulnerabilities related to the version 1.0.2 of the package
Out-of-bounds Read in concat-with-sourcemaps
Versions of concat-with-sourcemaps
before 1.0.6 allocates uninitialized Buffers when a number is passed as a separator.
Update to version 1.0.6 or later.