app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29572.json"