NuGet's MSBuild tasks reference MSBuild packages in order to implement the Task class, but all currently available versions of MSBuild packages have a transitive dependency on vulnerable versions of System.Security.Crypotgraphy.Xml. Therefore, NuGet will pin the version of S.S.C.Xml to 8.0.3, until new versions of MSBuild is published without the transitive package advisory.
NuGet's MSBuild tasks reference MSBuild packages in order to implement the Task class, but all currently available versions of MSBuild packages have a transitive dependency on vulnerable versions of System.Security.Crypotgraphy.Xml. Therefore, NuGet will pin the version of S.S.C.Xml to 8.0.3, until new versions of MSBuild is published without the transitive package advisory.