This affects all versions of package decal. The vulnerability is in the extend function.
CVSS Metrics