This is not _eslint_. This is _eslint-scope_ which is not included by default with ESLint itself.
What you're saying is anyhow wrong as far as I can see. ESLint-scope is included by ESLint. Current version uses ^4.0.0 and shouldn't be affected, but versions from before May has the affected ^3.7.1 dependency. This version is also included in webpack, making it a big target anyhow.
Yeah, it is.
$ json -j version dependencies.eslint-scope < `npm root -g`/eslint/package.json
{
"version": "4.19.1",
"dependencies.eslint-scope": "^3.7.1"
}