target = blank vulenrability

https://dev.to/ben/the-targetblank-vulnerability-by-example

in short:

use

rel="noopener noreferrer"

whenever a link is

target="_blank"