I am currently not a maintainer anymore, and due to academic reasons I do not have the time to fight with clashing dependencies.
The software has the following high level vulnerabilities at the moment:
Actively usable
Most likely not a problem, as vulnerability cannot be used
I did not have the time to investigate the second one further, but it is connected to file name processing, as we do not support any type of file uploads atm, this might be a non-issue for us