Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000442.json"