fig. 01 — GHSA-9q64-mpxx-87fg, the advisory selected below
// advisories
GHSA-9q64-mpxx-87fg
HIGH
Versions of ecstatic prior to 4.1.2, 3.3.2 or 2.2.2 are vulnerable to Open Redirect. The package fails to validate redirects, allowing attackers to craft requests that result in an HTTP 301 redirect to any other domains.