Allow arbitrary URLs, expect arbitrary code execution
Original Post:
We discussed this vulnerability during Episode 73 on 20 April 2021
Just an overview of how opening links is broken if you don’t check the schema and let the OS deal with it.