Depends on the pinned version. The pinned version might even have vulnerabilities themselves. The problem is trusting the ecosystem.