sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
{ "ubuntu_priority": "medium" }