All the vulnerabilities related to the version 2.0.2 of the package
JSZip contains Path Traversal via loadAsync
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Command Injection in lodash
lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.