All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
CVSS Metrics