An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.
https://github.com/hunvreus/devpush/releases/tag/0.3.2
https://github.com/hunvreus/devpush
https://gist.github.com/syphonetic/d4e519904aaa55dbd0e3b87a317660d1