Security vulnerability affects the xz package. Malicious code was discovered in the upstream tarballs of xz, starting with version 5.
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-NL28578.json"