Dependency `glob` has been identified as having a command injection vulnerability https://www.cve.org/CVERecord?id=CVE-2025-64756