Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.