osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query List in github.com/jmpsec/osctrl
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-4576" }
"https://vuln.go.dev/ID/GO-2026-4576.json"