If the vulnerability is purely an open redirect that doesn't work for me.
Clearly there was a hole in the software but I don't think open redirect is the likely initial problem.
Hopefully we will find out for sure in a few days.