Local File Read via Stored XSS in The Opera Browser
The vulnerability here is simply that Opera’s Pinboard feature allows pinning URLs starting with javascript:
creating a clickable link on a Pinboard that will execute JavaScript. Unfortunately (for the attacker) these tabs open in a new window and not within the Pinboard context unless middle clicking, then these links will trigger them within the Pinboard context.