Hello
Here is the link to the CVE: GHSA-5j98-mcp5-4vw2
The glob package should be updated to at least version 10.5.
Dependabot already created a PR for that update (good bot), it would be great to merge and publish an updated package quickly to fix that issue.
Thanks!