npcheck should at least show the top level module that pulled in a module with a reported CVE. Ideally the tree would be even better.