See Google Analytics - Moderately Critical - Cross Site Scripting - SA-CONTRIB-2016-042.
Security release
Security fix
Fixes security issue.
See OAuth2 Client- Moderately Critical - Cross Site Request Forgery - SA-CONTRIB-2016-044
Check the state parameter in server-side flow.