Don't TLS certs have domains they're valid for in the cert? (I admit it's been a while since I looked at this.) That would make them hard to phish.
I've pushed a fix.
If you can find a way to abuse a valid authentication to one site in order to gain access to another site, that sounds like a very firmly valid security issue needing investigated.