OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-24601.json"