The extension is vulnerable to CVE-2025-54798. Updating tmp to at least 0.2.4 should resolve the vulnerability.