The project depends on [`org.json:json:20230618`](https://github.com/google/closure-templates/blob/master/maven_install.json#L212). [That version](https://ossindex.sonatype.org/component/pkg:maven/org.json/json@20230618) has a [high scored vulnerability](https://ossindex.sonatype.org/vulnerability/CVE-2023-5072?component-type=maven&component-name=org.json/json).