Uglify bug
I was reading Feross Aboukhadijeh's course notes for CS 253 Web Security, specifically bcrypt's slides about real-world security, and an unexpected face popped up (mine). I filed a bug in the uglify project in 2015 and didn't think much more about it, but turns out, there's a blog post building on it as an exploit, a whole CVE in the national database and a critical assignment on GitHub.
Fun! I don't take any credit because I didn't even come up with a good reduced test case, Titus did more work on that, and Mihai actually made the fix. But it's cool to come across an old thread that had an unusually big impact.