The vulnerability allows arbitrary local file read by defining unsafe window options on a child window opened via window.open.
Ensure you are calling event.preventDefault() on all new-window events where the url or options is not something you expect.
9.0.0-beta.218.2.47.2.4If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-552"
],
"github_reviewed": true,
"github_reviewed_at": "2020-07-06T23:54:56Z",
"nvd_published_at": null,
"severity": "MODERATE"
}