All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
https://github.com/advisories/GHSA-7mwh-4pqv-wmr8
https://snyk.io/vuln/SNYK-JS-SCSSTOKENIZER-2339884