Improper Neutralization in a JavaScript context — CWE-79 (hardening). No CVE assigned at time of writing (1.0.275 released 2026-07-28). The upstream changelog states: “Strengthened the security of the Debug redirections feature of the plugin.”

The redirection debugger renders an inline