The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
"https://github.com/pypa/advisory-database/blob/main/vulns/django-unicorn/PYSEC-2021-369.yaml"