Xz package contains a vulnerability

Downgrading to xz 5.4.6 (lib32-xz also) ( till beginning of March in Manjaro Stable ) would be another way instead of updating?