Hi, passkit-generator creator here.
For things like that, it is likely better to write on Github. I found this thread "by mistake". I never heard of the CVE you are referring to, btw. The referred dependency is something you generally install with the examples, but I don't know what you are doing.
Topic:
App & System Services
SubTopic:
Wallet