op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
Published April 3, 2020.
Op-browser Project Op-browser