sanitize-url (aka @braintree/sanitize-url) before 6.0.1 allows XSS via HTML entities.
Fix available through Seal Security. No upgrade required, protect your application instantly.