Babel contains an open redirect vulnerability via redirect.php in the newurl parameter. An attacker can use any legitimate site using Babel to redirect user to a malicious site, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
View the template here CVE-2019-1010290.yaml
References:
https://untrustednetwork.net/en/2019/02/20/open-redirection-vulnerability-in-babel/