npm audit is unable to fix a a vulnerability because there is no version range on the loader-utils dependency (https://github.com/webpack/webpack-cli/blob/master/package.json#L123).

Updating this dependency and releasing v3.3.12 will fix the issue. (https://www.npmjs.com/advisories/1179/versions)