fig. 01 — GHSA-vvvv-983w-r7pv, the advisory selected below
// advisories
GHSA-vvvv-983w-r7pv
MODERATECVE-2026-42565
An open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter.