LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
"https://github.com/pypa/advisory-database/blob/main/vulns/oncall/PYSEC-2021-33.yaml"