This is not a fix for the vulnerability.
Just updating the dependency to the latest version.
@see https://yarnpkg.com/package/cross-env
Yes, I know that they recently released version 6.0 and in a short time 7.0.
If you open the `/css`, `/js`, or any other folder on the default server, you can see the list of files in the directory.
The `-Indexes` option forbids viewing directory files via the web interface.