Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).
https://github.com/gitpod-io/gitpod/releases/tag/2022.11.3
https://github.com/gitpod-io/gitpod/pull/17559
https://github.com/gitpod-io/gitpod/compare/release-2022.11.2...2022.11.3
https://github.com/gitpod-io/gitpod/commit/6771283c3406586e352337675b79ff2ca50f191b