@theopolis Recently people have observed, and started exploiting, differences in how URL parsers work.
https://github.com/orangetw/Tiny-URL-Fuzzer and the linked slide deck is pretty neat. Short form is that software libraries all parse slightly malformed URLs differently, this often means that you can craft something to pass a "not-evil" check, which is then fetched by something that parses it differently. I don't think there's a direct impact on osquery, but if a site had configured a front end to do some kind of validity check, before passing a URL to osquery, there would likely be some kind of exploit route.